August 3, 2026
- Jellyfin CVE-2026-35033 is an unauthenticated argument-injection flaw that yields code execution by manipulating FFmpeg arguments through the
level parameter, per Sonar. Fixed in 10.11.7.
· Vulnerabilities & Exploits
in God-Mode Access in N-able N-central Tops a Day of Fresh Exploits
June 26, 2026
- CVE-2026-8461 ("PixelSmash") — a heap OOB write in FFmpeg's MagicYUV decoder yields RCE via a crafted media file; a public exploit dropped. JFrog, PoC
· Vulnerabilities & Exploits
in Malware Weaponizes Prompt Injection to Sabotage AI Analysis as Gamaredon Retools Against Ukraine
June 25, 2026
- FFmpeg "PixelSmash" (CVE-2026-8461) in the libavcodec MagicYUV decoder enables RCE via crafted media files, putting video players, media servers, and NAS appliances at risk; fixed in FFmpeg 8.1.2. SecurityWeek, JFrog
· Vulnerabilities & Exploits
in Cisco SD-WAN Manager Zero-Day Gives Root via a Malicious CSV as Operation Endgame Smashes Amadey and StealC
June 24, 2026
- PixelSmash, a critical RCE in FFmpeg's MagicYUV decoder, lets a crafted media file execute code in any app using libavcodec — RCE on Jellyfin under certain conditions, and DoS in Kodi, Emby, Nextcloud, PhotoPrism, and OBS. Now patched. JFrog, BleepingComputer.
· Vulnerabilities & Exploits
in Two Netlogon Flaws Hit Domain Controllers as FortiBleed Lands in Finland
June 18, 2026
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel