PT-2026-47173 · Undefined · Undefined

CVE-2026-39218

·

Published

2026-06-07

·

Updated

2026-06-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
A security startup called depthfirst deployed an autonomous AI agent against FFmpeg's ~1.5 million lines of C code. The result: 21 confirmed zero-day vulnerabilities — including a stack overflow in the AV1 RTP depacketizer that's a network-reachable RCE exploitable with a single 183-byte RTP packet over RTSP.
The economics are wild:
• Cost: ~$1,000 in cloud compute
• Human audit equivalent: $200K–$500K
• One bug was 23 years old — introduced in 2003
• Nine CVEs assigned so far (CVE-2026-39210 through CVE-2026-39218)
But here's the real problem: only 6% of vulnerabilities from Anthropic's Project Glasswing have been patched. We've automated finding bugs — but not fixing them
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-39218

Affected Products

Undefined