CVE-2026-56711: Videolan Vlc Media Player

High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.

VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.

Affected products

  • Videolan Vlc Media Player: from 3.0.0, up to and including 3.0.23

Published 2026-09-09. Last modified 2026-09-18.