All incidents

FFmpeg MagicYUV decoder flaw (CVE-2026-8461) enables remote code execution

vulnerabilityclosedJun 23, 2026 — Jun 26, 2026
FFmpeg MagicYUV decoder flaw (CVE-2026-8461) enables remote code execution

A newly disclosed flaw in FFmpeg’s MagicYUV video decoder lets attackers execute arbitrary code by supplying a specially crafted media file, a vulnerability tracked as CVE-2026-8461 and rated 8.8 on the CVSS scale.

The issue stems from a heap out-of-bounds write caused by incorrect handling of frame allocation and chroma plane heights within the libavcodec library, allowing memory corruption that can be hijacked for code execution, as detailed in the CVE record.

Versions prior to 8.1.2 are affected, and the flaw can be triggered through AVI MKV or MOV files processed by tools such as ffmpegthumbnailer, media servers like Jellyfin and Nextcloud, or embedded in NAS appliances and smart TVs, according to reports from securityonline.info and malwarebytes.com.

Although no specific threat actor has been named, security researchers have observed active exploitation attempts in the wild, with proof‑of‑concept files circulating that crash vulnerable instances or spawn a shell, as noted in coverage by securityweek.com.

Administrators are advised to upgrade to FFmpeg 8.1.2 or later, to disable the MagicYUV decoder if immediate patching is not feasible, and to restrict automatic ingestion of untrusted video content until the fix is applied.

Additionally, monitoring application logs for unexpected decoder crashes or spikes in CPU usage can help detect exploitation attempts, and reviewing which services rely on FFmpeg for media transmittal will prioritize patching efforts.

Intelligence briefing updated Jun 26, 2026

CVE-2026-8461 8.8
Root sourcejfrog.com
Timeline Coverage

Swipe to explore timeline