CVE-2026-73324

Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build configuration.

  • Published Sep 9, 2026
  • CVSS 5.3 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-73324 at the National Vulnerability Database