PT-2026-47173 · Undefined · Undefined
CVE-2026-39218
·
Publicado
2026-06-07
·
Atualizado
2026-06-09
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
A security startup called depthfirst deployed an autonomous AI agent against FFmpeg's ~1.5 million lines of C code. The result: 21 confirmed zero-day vulnerabilities — including a stack overflow in the AV1 RTP depacketizer that's a network-reachable RCE exploitable with a single 183-byte RTP packet over RTSP.
The economics are wild:
• Cost: ~$1,000 in cloud compute
• Human audit equivalent: $200K–$500K
• One bug was 23 years old — introduced in 2003
• Nine CVEs assigned so far (CVE-2026-39210 through CVE-2026-39218)
But here's the real problem: only 6% of vulnerabilities from Anthropic's Project Glasswing have been patched. We've automated finding bugs — but not fixing them
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Undefined