[UPDATE] [hoch] ffmpeg: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in ffmpeg ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, um beliebigen Programmcode auszuführen, und um einen Denial of Service Angriff durchzuführen.
CSIRTS triage
- What
- Multiple vulnerabilities in ffmpeg enable remote code execution, arbitrary code execution, and denial-of-service attacks.
- Who is affected
- All ffmpeg deployments consuming untrusted media input are affected.
- Urgency
- High severity; no active exploitation reported but RCE capability makes this critical.
- Action
- Upgrade ffmpeg to the latest patched version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ffmpeg
Get an email when a new ffmpeg advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2939
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-751410.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-751420.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-751430.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-751440.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-751450.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-751460.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-751470.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-75141 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75142 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75143 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75144 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75145 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75146 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75147 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownUSN-8716-1: FFmpeg vulnerabilitiesubuntu
- highCVE-2026-75147: FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavfo…nvd
- highCVE-2026-75146: FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/d…nvd
- mediumCVE-2026-75145: FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP…nvd
- highCVE-2026-75144: FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac R…nvd
- criticalCVE-2026-75143: FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (liba…nvd
- highCVE-2026-75142: FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavforma…nvd
- highCVE-2026-75141: FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writ…nvd
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] Red Hat Enterprise Linux (libreswan): Mehrere Schwachstellen ermöglichen Denial of Service2026-09-08
- medium[UPDATE] [mittel] Red Hat Enterprise Linux (sg3_utils): Schwachstelle ermöglicht Ausführen von beliebigem Prog…2026-09-08
- medium[UPDATE] [mittel] Golang Go-Module (Net, Image, Crypto: Mehrere Schwachstellen2026-09-08
- medium[UPDATE] [mittel] gzip: Mehrere Schwachstellen2026-09-08
- high[UPDATE] [hoch] Golang Go: Mehrere Schwachstellen2026-09-08