[NEW] [high] ffmpeg: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in ffmpeg to perform an unspecified attack, execute arbitrary code, and perform a denial of service attack.
CSIRTS triage
- What
- Multiple vulnerabilities in ffmpeg enable remote code execution, arbitrary code execution, and denial-of-service attacks.
- Who is affected
- All ffmpeg deployments consuming untrusted media input are affected.
- Urgency
- High severity; no active exploitation reported but RCE capability makes this critical.
- Action
- Upgrade ffmpeg to the latest patched version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ffmpeg
Get an email when a new ffmpeg advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2939
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-751410.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-751420.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-751430.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-751440.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-751450.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-751460.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-751470.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-75141 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75142 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75143 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75144 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75145 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75146 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75147 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-75147: FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavfo…nvd
- highCVE-2026-75146: FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/d…nvd
- mediumCVE-2026-75145: FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP…nvd
- highCVE-2026-75144: FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac R…nvd
- criticalCVE-2026-75143: FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (liba…nvd
- highCVE-2026-75142: FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavforma…nvd
- highCVE-2026-75141: FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writ…nvd
Recent advisories for ffmpeg
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownUSN-8680-1: FFmpeg vulnerabilitiesubuntu · 2026-08-25
- high[NEW] [high] ffmpeg: Multiple vulnerabilitiescert-bund · 2026-08-25
- mediumCVE-2026-78430: A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the…nvd · 2026-08-24
- unknownUSN-8671-1: FFmpeg vulnerabilitiesubuntu · 2026-08-24
- medium[NEW] [medium] ffmpeg: Multiple vulnerabilities allow code execution and DoScert-bund · 2026-08-24
- high[NEW] [high] ffmpeg: Multiple vulnerabilitiescert-bund · 2026-08-24
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25