All findings

CVE-2026-39210 + 8 more high

DepthFirst publishes twenty-one fixed FFmpeg zero-days

DepthFirst says its autonomous agents found 21 reachable FFmpeg vulnerabilities; nine received consecutive CVEs and twelve additional issues were fixed upstream without public CVE IDs.

Bug class
Heap and stack overflows, integer overflow, and out-of-bounds access
Affected codebase
FFmpeg
Credited system
DepthFirst
Disclosed
June 2, 2026
Attribution
Self-reported attribution
Severity
high
Source status: DepthFirst's primary campaign report identifies the autonomous workflow, reproducible inputs, nine CVEs, and twelve additional fixed DFVULN records. Upstream fixes and CVE assignments corroborate acceptance.

Summary

The campaign spans FFmpeg demuxers, muxers, codecs, RTP handling, scaling, and command-line parsing. The nine CVE-backed issues are CVE-2026-39210 through CVE-2026-39218. Twelve more accepted fixes are identified as DFVULN-116 through DFVULN-127.

Counting correction

DepthFirst’s prose says eight issues received CVEs, but the page lists nine distinct identifiers. Bugflation follows the explicit list. The twelve non-CVE fixes remain part of this one campaign entry and do not increase the unique-CVE counter.

Attribution

DepthFirst supplies the autonomous-agent claim; upstream fixes and CVE records corroborate the vulnerabilities. The entry is therefore self-reported AI attribution with independent acceptance.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.