There will only be an alert if that photo is extremely similar to an image in the NCMEC database, AND there are numerous other such photos on the account that match. The threshold number of matches to trigger an alert is tuned for a 1/trillion chance of false positive.
Furthermore, if you were using say Google Photos to store your images, then you were already subject to this vulnerability.