JFrog Uncovers PixelSmash, a 16-Year-Old FFmpeg Flaw Exploitable via a 50 KB Video File
JFrog researchers turned a 16-year-old FFmpeg decoder bug, CVE-2026-8461, into working remote-code-execution exploits against Jellyfin and Nextcloud using one 50 KB video file.