CVE-2026-107675

CVE-2026-107675 published: FFmpeg through 9.0.2 contains a missing host key verification vulnerability in the libssh-based sftp protocol handler that allows network attackers to impersonate SFTP servers. Attackers performing man-in-the-middle, DNS, or ARP spoofing can capture passwor...

View full NVD advisory → ← Back to CVE watch