PT-2026-47173 · Undefined · Undefined

CVE-2026-39218

·

Publicado

2026-06-07

·

Atualizado

2026-06-09

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
A security startup called depthfirst deployed an autonomous AI agent against FFmpeg's ~1.5 million lines of C code. The result: 21 confirmed zero-day vulnerabilities — including a stack overflow in the AV1 RTP depacketizer that's a network-reachable RCE exploitable with a single 183-byte RTP packet over RTSP.
The economics are wild:
• Cost: ~$1,000 in cloud compute
• Human audit equivalent: $200K–$500K
• One bug was 23 years old — introduced in 2003
• Nine CVEs assigned so far (CVE-2026-39210 through CVE-2026-39218)
But here's the real problem: only 6% of vulnerabilities from Anthropic's Project Glasswing have been patched. We've automated finding bugs — but not fixing them
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-39218

Produtos afetados

Undefined