Jellyfin — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
June 22, 2026
Last Seen
June 24, 2026

Jellyfin is a technology platform tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.

Jellyfin is a technology platform tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed June 22, 2026; most recent activity June 24, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Hole in widely — Csoonline · June 24, 2026
  • Critical FFmpeg flaw discovered: just watching a video can fully compromise your system — Cybernews · June 23, 2026
  • FFmpeg fixes PixelSmash flaw in widely used video decoder — Bleepingcomputer · June 22, 2026

Frequently asked questions

What is Jellyfin?

Jellyfin is a technology platform tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.

Is Jellyfin still active?

The most recent intelligence report mentioning Jellyfin on ThreatCluster is dated June 24, 2026. Activity was first observed June 22, 2026, giving a tracked span from then to June 24, 2026.

What is Jellyfin associated with?

Across ThreatCluster reporting, Jellyfin most frequently co-occurs with APT20/Cozy Bear, DDoS, Supply Chain Attack, Zero-day Exploit, JFrog, among 12 tracked related entities.

What are the latest developments involving Jellyfin?

The most significant recent cluster is “Critical FFmpeg Vulnerability Enables Remote Code Execution via Malicious Media Files” (9 articles · Updated June 23, 2026). Jellyfin appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on Jellyfin?

Jellyfin appears in 3 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown