1.
JFrog discloses PixelSmash (CVE-2026-8461), a CVSS 8.8 FFmpeg MagicYUV heap bug where a crafted 50 KB media file yields RCE against apps like Jellyfin and Nextcloud; fixed in 8.1.2.
Skip to content
Curated 1 security research writeups, vulnerability advisories and exploitation analyses for CVE-2026-8461.