Skip to content
Critical FFmpeg Vulnerability Enables Remote Code Execution via Malicious Media Files

Critical FFmpeg Vulnerability Enables Remote Code Execution via Malicious Media Files

First seen 23 Jun 2026, 09:09 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 24, 2026 at 08:46 UTC

A critical vulnerability in FFmpeg's MagicYUV decoder, tracked as CVE-2026-8461, allows attackers to exploit heap out-of-bounds writes to crash systems or execute remote code. Discovered by JFrog, the flaw affects a wide range of applications that utilize FFmpeg, including media servers like Jellyfin and Nextcloud, as well as desktop applications such as Kodi and VLC. Users can be compromised simply by processing malicious media files, including during thumbnail generation by file managers. The vulnerability has a CVSS score of 8.8, indicating high severity, and a patch (version 8.1.2) has been released. Exploitation requires no special privileges, making it particularly dangerous. Security teams are urged to upgrade immediately to mitigate risks. The potential impact is extensive due to FFmpeg's widespread use across various platforms and devices.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2026-06-18
CVE-2026-8461 published
A critical out-of-bounds write vulnerability in FFmpeg's MagicYUV decoder was disclosed, allowing for remote code execution and denial-of-service.
nvd.nist.gov
2026-06-22
FFmpeg releases patch version 8.1.2
FFmpeg released an urgent patch to address the critical vulnerability in the MagicYUV decoder, urging users to upgrade immediately.
Bleepingcomputer
2026-06-23
Security researchers warn of exploitation risks
JFrog researchers highlighted the potential for remote code execution and denial-of-service attacks through the vulnerability, emphasizing its widespread impact.
Cybernews
2026-06-24
Media outlets report on vulnerability's implications
Multiple news outlets reported on the critical nature of the FFmpeg vulnerability, stressing the urgent need for users to apply the patch.
Csoonline

More articles in this cluster (9)

Following this threat?

Track APT20/Cozy Bear, JFrog and CVE-2026-8461 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed