2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57272 — GeoWebPlayer: #### byPass command index-out-of-bound

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57272

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` CVSSv3.1 8.3 (HIGH)

CWECWE 129VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57271 — GeoWebPlayer: (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57271

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. #### pause command index-out-of-bound CVSSv3.1 8.3 (HIGH)

CWECWE 129VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57270 — GeoWebPlayer: (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57270

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` CVSSv3.1 8.3 (HIGH)

CWECWE 129VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57269 — GeoWebPlayer: (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57269

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` CVSSv3.1 8.3 (HIGH)

CWECWE 129VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57268 — GeoWebPlayer: The release function call ([3]) is executed using a function pointer which will be

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57268

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` CVSSv3.1 8.3 (HIGH)

CWECWE 129VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57267 — GeoWebPlayer: (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57267

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` CVSSv3.1 8.3 (HIGH)

CWECWE 129VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57266 — GeoWebPlayer: (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57266

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` CVSSv3.1 8.3 (HIGH)

CWECWE 129VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57265 — GeoWebPlayer: (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57265

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` CVSSv3.1 8.3 (HIGH)

CWECWE 129VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-57264 — GeoWebPlayer: (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57264

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` CVSSv3.1 8.3 (HIGH)

CWECWE 129VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-13132 — GeoWebPlayer: (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13132

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` CVSSv3.1 8.3 (HIGH)

CWECWE 129VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-13131 — GeoWebPlayer: (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13131

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` CVSSv3.1 8.3 (HIGH)

CWECWE 129VNDGeowebplayerTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-02
2026-07-02 04:17Z
HIGH

CVE-2026-13125 — GeoWebPlayer: (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-13125

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. In order to access the websocket server, no authentication is required. As such, any malicious website can attemp CVSSv3.1 8.8 (HIGH)

CWECWE 306VNDGeowebplayerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-02
2026-07-02 00:00Z
CRIT

Vect and TeamPCP partner for ransomware campaigns

Sophos X-Ops·news.sophos.comCVE-2025-55182in the wild

Sophos CTU researchers document a formal operational partnership between Vect (a RaaS operation launched December 2025) and TeamPCP (a credential-harvesting group), combining supply chain compromise capabilities with ransomware deployment infrastructure. From March–May 2026, TeamPCP executed a coordinated campaign compromising Trivy, Checkmarx, Bitwarden CLI, LiteLLM, and Telnyx, exfiltrating ~300GB of compressed credentials (500k+ credential sets) and propagating CanisterWorm across 48+ npm packages, affecting 1,000+ enterprise SaaS environments. The partnership has operationalized ransomware deployment against supply-chain-compromised organizations, with at least one confirmed Vect deployment using TeamPCP-sourced credentials.

SRFApplicationTACTA0001TACTA0006TACTA0040SRFSupply ChainSWLitellmSWBitwardenSWCheckmarx
92
Edit Score
2026-07-02
2026-07-02 00:00Z
INFO

Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3

Elastic Security Labs·elastic.co

Elastic Security Labs published a detailed technical writeup of their internal agentic SOC architecture built on Elastic Workflows and Agent Builder. The system automates alert triage using deterministic ES|QL queries for obvious false positives, domain-specific AI agents for deeper investigation across endpoint/cloud/SaaS, and a final synthesis agent that produces analyst-ready verdicts—reducing manual triage time from 30 minutes to under 3 minutes while controlling inference costs through selective LLM usage.

SRFApplicationTACTA0007SRFCloudSWElasticsearchSWKibanaVNDElasticTYPResearchTECT1589
68
Edit Score
2026-07-02
2026-07-02 00:00Z
INFO

Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3

Elastic Security Labs·elastic.co

Elastic Security Labs published a technical deep-dive on their internal agentic SOC architecture that automates alert triage using deterministic ES|QL queries, specialized AI agents, and a final review synthesis layer. The system reduces manual triage time from 30 minutes to under 3 minutes by closing obvious false positives with zero token cost, routing ambiguous alerts to domain-specific agents (macOS, Windows, Linux, AWS, Azure, GCP, Okta), and assembling findings into structured Kibana cases before analyst review.

SRFApplicationTACTA0007SRFCloudSWElastic SecuritySWKibanaSWElastic WorkflowsVNDElasticTYPResearch
68
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14432 — Use: after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14432

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14431 — Type: Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14431

Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14430 — Integer: overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14430

Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 472TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14429 — Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14429

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14428 — Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14428

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14427 — Heap: buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14427

Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14425 — Use: after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14425

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14424 — Use: after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14424

Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
CRIT

CVE-2026-14423 — Type: Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14423

Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 843VNDTypeTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-07-01
2026-07-01 23:16Z
HIGH

CVE-2026-14422 — Out: of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14422

Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 125CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score