Critical vulnerabilities found in libSRT

Posted July 20, 2026

Zixi has been informed of two critical vulnerabilities within libSRT (open source) which Zixi uses within the Zixi Broadcaster product.

  1. Denial of service vulnerability [CVE-2026-55869: Heap-Based Buffer Overflow in KMREQ Handling]
  2. Remote encryption downgrade capabilities [CVE-2026-55868: Encryption State Machine Downgrade]

As Zixi’s SRT integration uses libSRT, within 24hrs of the official libSRT patch (v1.5.6) released on July 20th, Zixi released Zixi Broadcaster v18.13 as well as a v19.0 patch that addresses the SRT library update.

It is recommended to upgrade to either v18.13 or v19.0 to ensure protection from these vulnerabilities. 

To upgrade:

  1. Download desired version from portal.zixi.com (v18.13v19.0)
    • Windows builds will be ready very shortly if not available
    • NOTE: v19.0 is a re-release, so customers currently running v19.0 will also need to upgrade.
  2. Upgrade Zixi Broadcaster:
    1. Via Broadcaster GUI
    2. Via ZEN Master

Please note that this vulnerability is across all previously released SRT Library versions and likely affects other products with SRT capabilities on the market. The Zixi protocol and other protocols supported by the Zixi platform are unaffected by these vulnerabilities.

For more information or assistance, feel free to reach out to support@zixi.com