logo

21 0-Day Vulnerabilities in FFmpeg Enables Remote Code Execution Attacks

ID: b5337203-8a5d-5a26-b1b9-30417912fc9d

STIX ID: report--b5337203-8a5d-5a26-b1b9-30417912fc9d

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Abinaya

...
...

Depthfirst's autonomous security agent discovered 21 zero-day vulnerabilities in FFmpeg — including a critical heap buffer overflow in the AV1 RTP depacketizer that enables remote code execution via a single 183‑byte RTP/RTSP packet. The flaws span demuxers, decoders, and network-facing components used across browsers, streaming platforms, CCTV/surveillance, and cloud transcoding; a PoC exists and several CVEs have been assigned. Administrators should apply patches immediately and audit any pipelines that process untrusted RTSP/RTP streams.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.