#5
SecurityWeek
general
June 23, 2026 at 11:48 UTC
FFmpeg PixelSmash Flaw Allows RCE on Video Players, Media Servers, NAS Appliances
By Ionut Arghire
AI Summary
A newly disclosed FFmpeg vulnerability dubbed 'PixelSmash' allows remote code execution via crafted media files in any application using FFmpeg's libavcodec library, including Jellyfin servers, and can trigger denial-of-service in Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. Given FFmpeg's ubiquity across media servers, NAS appliances, and video players, the attack surface is extremely broad. Administrators running any of these applications should apply the FFmpeg patch immediately and audit media ingestion pipelines.
Relevance score: 86.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →