Desk live·
ForensicPost
Cloud/Vulnerabilities/File 26-0328

27-year-old OpenBSD Flaw and 16-year-old FFmpeg Bug Found by Automated Research

Reported findings include a 27-year-old vulnerability in OpenBSD and a 16-year-old bug in FFmpeg, both of which passed human code review and automated testing for their entire lives.

Constructed geometry · not a chart of case data
TargetLong-lived open-source code
ActorResearch consortium
D. Kennedy11 min readConfidence: medium2 sources reviewed

Among the reported findings from the programme filed at 26-0404 are a 27-year-old vulnerability in OpenBSD and a 16-year-old bug in FFmpeg. Both are described as having survived every prior round of human code review and automated testing.

OpenBSD in particular is a project whose reputation rests on code auditing. If a defect can persist there for 27 years, the finding is about the limits of review rather than about that project.

Two Things This Does Not Mean

It does not mean the software was insecure for 27 years in any practical sense. A defect nobody had found was not being exploited, and the security a project delivered over that period was real.

It also does not mean human review is worthless. Review catches an enormous volume of defects before release; what it evidently does not catch reliably is a particular class that requires holding more context than a reviewer can.

What It Does Mean Is Uncomfortable

Age is not evidence of correctness. "Battle-tested" and "mature" are used as security arguments in dependency selection, and this finding undercuts them: a component may have been examined by thousands of people for decades and still contain an exploitable defect that nobody had the technique to find.

The corollary is that every long-lived codebase should now be assumed to contain findings of this kind, whether or not anyone has looked yet.

Who Else Can Look

The capability that found these is available to anyone who can pay for compute. There is no property of it that restricts use to a disclosure programme, which is the concern filed at 26-0315.

A defect that survived 27 years of review is exactly the category an adversary would most value: present in an enormous deployed base, with no patch, and no reason for anybody to be watching for its exploitation.

How we reported this

Compiled from published reporting on the coalition’s findings, listed below. Ages and characterisations are as reported; we have not examined the defects. Corrections: corrections@forensicpost.com.

Sources
  1. AI found a 27-year-old bug: Project Glasswing dev guide 2026Nexgismo
  2. Project Glasswing identifies over 10,000 critical vulnerabilities in first month using AICrypto Briefing
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary