FFmpeg has fixed CVE-2026-8461, a high-severity MagicYUV decoder flaw that researchers say can crash media apps and, in some cases, enable remote code execution on Jellyfin servers.
·