Just letting the SF team know, the FFMpeg library needs updating to version 8.1.2 or later.
The vulnerability is called “PixelSmash” (tracked as CVE-2026-8461), a critical heap out-of-bounds write in FFmpeg’s MagicYUV decoder.
Although having an older version provided with SF might not create an issue with systems out there, it is just best to not have older version present on any system!
Anyone that has Codec packs or FFMpeg itself installed should update to the later versions as well.
This reminds me of a long time ago when malicious code was attached to JPG images.