CVE-2026-56711

High7.0Published on September 9, 2026

VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.

CVSS score7.0 / 10CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness type (CWE)CWE-190, CWE-787

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database