started · updated
Critical Software and Hardware Flaws Discovered in FFmpeg, Lantronix, Cisco and Ubiquiti
A series of high‑severity vulnerabilities have been disclosed across widely used software and networking hardware.
The FFmpeg multimedia framework contains a heap out‑of‑bounds write bug in its MagicYUV decoder (CVE‑2026‑8461, dubbed “PixelSmash”). Researchers demonstrated remote code execution on Jellyfin media servers and denial‑of‑service crashes on applications such as Kodi, Nextcloud and OBS Studio. The flaw affects any Linux system that uses FFmpeg for thumbnailing, metadata extraction or video transcoding; FFmpeg 8.1.2 released on June 17 2026 addresses the issue.
Lantronix’s EDS5000 remote‑management appliance is vulnerable to a code‑injection flaw (CVE‑2025‑67038) that allows attackers to execute commands with root privileges via the username parameter. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed the bug in its Known Exploited Vulnerabilities (KEV) catalog, noting active exploitation in the wild.
Cisco Unified Communications Manager (Unified CM) and its Session Management Edition are affected by an SSRF and arbitrary file‑write vulnerability (CVE‑2026‑20230). The flaw enables unauthenticated attackers to write files to the underlying operating system and ultimately gain root access. Defused and other researchers have observed active exploitation using crafted HTTP requests.
Ubiquiti’s UniFi OS suffers multiple flaws, the most critical being an improper access‑control issue (CVE‑2026‑34908) that can be leveraged to change system configurations or execute commands. Two additional bugs (CVE‑2026‑34909, CVE‑2026‑34910) allow path traversal and command injection. CISA has added these to its KEV list and urged patching by June 26 2026.
Separately, vulnerability‑management platform NinjaOne has integrated CISA’s KEV intelligence, now displaying KEV status alongside CVSS scores to help organizations prioritize remediation of actively exploited flaws.