CVE-2026-40962 is a critical integer overflow vulnerability affecting FFmpeg versions prior to 8.1, specifically in the CENC (Common Encryption) subsample data handling within libavformat/mov.c that leads to out-of-bounds memory writes. This vulnerability impacts any system or application utilizing vulnerable FFmpeg versions for media processing, particularly those handling encrypted multimedia content. The vulnerability carries a CVSS score of 9.8 (Critical) with a network-based attack vector that requires no authentication, low complexity, and no user interaction, making it highly exploitable. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code, compromise system confidentiality and integrity, and cause denial of service through a specially crafted media file. The vulnerability currently shows no evidence of active exploitation in the wild and has not been added to CISA's Known Exploited Vulnerabilities catalog. While the EPSS score of 0.0001 indicates minimal current exploitation probability, the extremely low threshold combined with the critical severity rating suggests organizations should prioritize updating to FFmpeg 8.1 or later as a precautionary measure, particularly for systems processing untrusted media files.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.1, < 8.1CPE match | cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* | ||
< 8.1CPE matchmatch criteria | cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.