Multiple FFmpeg Vulnerabilities Discovered Affecting Ubuntu Systems

Multiple FFmpeg Vulnerabilities Discovered Affecting Ubuntu Systems

First seen 26 Aug 2026, 00:24 UTC Ubuntu 45.9

Article Content

Browse articles
ThreatCluster

Two separate vulnerabilities in FFmpeg were reported, discovered by Adrian Junge. The first set of vulnerabilities (CVE-2026-66036, CVE-2026-66039, CVE-2026-66038) was published on July 24, 2026, and affects various media files, potentially allowing attackers to execute arbitrary code or obtain sensitive information. The second set (CVE-2026-70628, CVE-2026-70632), published on August 6, 2026, specifically impacts Ubuntu 22.04 LTS and 24.04 LTS, also allowing for denial of service or arbitrary code execution. Both vulnerabilities can be mitigated by standard system updates. Users are encouraged to update their systems to the latest package versions to ensure protection. The vulnerabilities pose a risk primarily to users of the affected Ubuntu versions.

Key Points: • Two sets of vulnerabilities in FFmpeg discovered by Adrian Junge. • CVE-2026-66036 and CVE-2026-66039 allow arbitrary code execution. • CVE-2026-70628 and CVE-2026-70632 specifically affect Ubuntu 22.04 LTS and 24.04 LTS.

Timeline

2026-07-24
CVE-2026-66036 and CVE-2026-66039 published
FFmpeg vulnerabilities disclosed that may allow arbitrary code execution or sensitive information exposure.
Ubuntu
2026-07-24
CVE-2026-66038 published
Another FFmpeg vulnerability disclosed that could lead to sensitive information exposure.
Ubuntu
2026-08-06
CVE-2026-70628 and CVE-2026-70632 published
New vulnerabilities in FFmpeg disclosed, affecting Ubuntu 22.04 LTS and 24.04 LTS, allowing denial of service or arbitrary code execution.
Ubuntu
2026-08-25
USN-8680-1 advisory released
Ubuntu published an advisory detailing the latest FFmpeg vulnerabilities and recommended system updates.
Ubuntu