← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 12, 2026 · 14:31via Cyber Security News

Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory

Brief

Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory.

The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.

  • 0 through 3.
  • 23 and require a victim to open a specially crafted media file or playlist entry.

Fabian Wahle of Hap Security discovered the vulnerabilities. CVE-2026-56711 carries a high severity rating with a CVSS score of 8. 6, while CVE-2026-73324 is rated medium severity with a CVSS score of 6.

  • Both issues were disclosed on September 9, 2026.

CVE-2026-56711 is an integer overflow and out-of-bounds write vulnerability in VLC’s picture-buffer allocation logic. The flaw is associated with CWE-190, Integer Overflow or Wraparound, and CWE-787, Out-of-bounds Write.

Read more on Cyber Security News→