boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-56711

VideoLAN VLC media player — VLC media player 3.0.0 through 3.0.23 memory corruption vulnerability
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   H   N   N   P   H   H   H    7.3   .0012    1.7     —
AFFECTED
  Product           Versions  Fixed
  VLC media player  3.0.0 –   —
TIMELINE
  Jun 22  Reserved by VulnCheck
  Sep 9   Published (CNA: VulnCheck)
  Sep 14  RESCORED — CVE-2026-56711 (VideoLAN VLC media player). CVSS 8.6 → 7.3 (NVD).
CWE-190, CWE-787 · CNA: VulnCheck · CVSS v4.0 · 6 references · NVD status: Deferred

Description

VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
June 22, 2026ReservedReserved by VulnCheck
September 9, 2026PublishedPublished (CNA: VulnCheck)
September 14, 2026RESCOREDRESCORED — CVE-2026-56711 (VideoLAN VLC media player). CVSS 8.6 → 7.3 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
VideoLANVLC media player—3.0.0—

Weaknesses

CWE-190 · CWE-787

References (6)

Related

Authoritative record: CVE-2026-56711 at cve.org

Vendors: videolan

Weaknesses: CWE-190 · CWE-787

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-56711 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.