CVE-2026-8461 is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 7 intelligence report mentions.
CVE-2026-8461 is a vulnerability tracked across 1 threat cluster and 7 intelligence report mentions on ThreatCluster. First observed June 22, 2026; most recent activity July 27, 2026.
A critical vulnerability in FFmpeg's MagicYUV decoder, tracked as CVE-2026-8461, allows attackers to exploit heap out-of-bounds writes to crash systems or execute remote code. Discovered by JFrog, the flaw affects a…
CVE-2026-8461 is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 7 intelligence report mentions.
The most recent intelligence report mentioning CVE-2026-8461 on ThreatCluster is dated July 27, 2026. Activity was first observed June 22, 2026, giving a tracked span from then to July 27, 2026.
Across ThreatCluster reporting, CVE-2026-8461 most frequently co-occurs with APT20/Cozy Bear, DDoS, Denial of Service, Remote Code Execution, Supply Chain Attack, among 12 tracked related entities.
The most significant recent cluster is “Critical FFmpeg Vulnerability Enables Remote Code Execution via Malicious Media Files” (9 articles · Updated June 23, 2026). CVE-2026-8461 appears across 1 threat cluster in total, listed above with sources.
CVE-2026-8461 appears in 7 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.