Bleepingcomputer Critical FFmpeg Vulnerability Enables Remote Code Execution via Malicious Media Files
Article Content
- •CVE-2026-8461 allows remote code execution via malicious media files.
- •The vulnerability affects numerous applications, including Jellyfin, Kodi, and VLC.
- •Users are urged to upgrade to FFmpeg version 8.1.2 to mitigate risks.
A critical vulnerability in FFmpeg's MagicYUV decoder, tracked as CVE-2026-8461, allows attackers to exploit heap out-of-bounds writes to crash systems or execute remote code. Discovered by JFrog, the flaw affects a wide range of applications that utilize FFmpeg, including media servers like Jellyfin and Nextcloud, as well as desktop applications such as Kodi and VLC. Users can be compromised simply by processing malicious media files, including during thumbnail generation by file managers. The vulnerability has a CVSS score of 8.8, indicating high severity, and a patch (version 8.1.2) has been released. Exploitation requires no special privileges, making it particularly dangerous. Security teams are urged to upgrade immediately to mitigate risks. The potential impact is extensive due to FFmpeg's widespread use across various platforms and devices.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track APT20/Cozy Bear, JFrog and CVE-2026-8461 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…