LIVE · cybersecurity feed
Live wire
CVE-2026-28739high

Multiple Vulnerabilities Found in WolfSSL, GeoVision, and VTK-DICOM

Researchers have disclosed several vulnerabilities affecting WolfSSL, GeoVision, and VTK-DICOM. The issues include improper input validation and integer underflow in WolfSSL, and a range of problems in GeoVision such as memory corruption, OS command injection, buffer overflows, and privilege escalation. These vulnerabilities have been addressed by the respective vendors.

zeroday.news · 23d ago

Multiple vulnerabilities have been identified and patched in WolfSSL, GeoVision, and VTK-DICOM, according to a recent disclosure by Cisco Talos. The vulnerabilities, discovered by the Talos Vulnerability Discovery & Research team, have all been addressed by their respective vendors in accordance with Cisco's disclosure policy.

WolfSSL, an open-source product providing lightweight and embedded security solutions for secure data transfer, was found to have three vulnerabilities. Ankur Tyagi of Cisco Talos discovered two improper input validation flaws, tracked as TALOS-2026-2409 (CVE-2026-28739) and TALOS-2026-2410 (CVE-2026-25106). Additionally, an integer underflow vulnerability, TALOS-2026-2408 (CVE-2026-33091), was also identified.

GeoVision, a company specializing in security technologies including cameras, monitoring solutions, access control, and machine identification, had the largest number of reported issues. Philippe Laulheret of Cisco Talos uncovered fourteen advisories covering a total of 37 CVEs across GeoVision products. These include memory corruption vulnerabilities (TALOS-2026-2411, CVE-2026-12488), multiple OS command injection vulnerabilities (TALOS-2026-2379 covering CVE-2026-12486, CVE-2026-12849, CVE-2026-12850, CVE-2026-12851, and TALOS-2025-2326 covering CVE-2026-42364), and several buffer overflow vulnerabilities (TALOS-2026-2377 covering CVE-2026-12485, CVE-2026-12846, CVE-2026-12847, CVE-2026-12848).

Further GeoVision vulnerabilities include stack overflow issues (TALOS-2026-2369 for CVE-2026-42370, and TALOS-2026-2333 for CVE-2026-7372, CVE-2026-42369), and privilege escalation vulnerabilities (TALOS-2026-2329 for CVE-2026-42368, and TALOS-2026-2328 for CVE-2026-42367). Reflected cross-site scripting (XSS) vulnerabilities were also found (TALOS-2026-2327 covering CVE-2026-7371, CVE-2026-42366).

Other issues in GeoVision products include a guessable session cookie vulnerability (TALOS-2025-2332, CVE-2026-42365) and an insufficient encryption vulnerability (TALOS-2025-2322, CVE-2026-7161). A series of stack-based buffer overflow vulnerabilities were grouped under TALOS-2026-2375 (CVE-2026-57273 through CVE-2026-57278). Out-of-bounds read vulnerabilities were identified under TALOS-2026-2373 (CVE-2026-13131, CVE-2026-13132, and CVE-2026-57264 through CVE-2026-57272). Finally, a lack of authentication vulnerability was reported as TALOS-2026-2370 (CVE-2026-13125).

The Virtualization Toolkit (VTK), an open-source software solution for scientific data handling and 3D rendering, also had a vulnerability in its DICOM API. This API allows VTK users to parse Digital Imaging and Communications in Medicine (DICOM) medical data. Emmanuel Tacheau of Cisco Talos discovered a heap-based buffer overflow vulnerability, identified as TALOS-2026-2366 (CVE-2026-22879), in VTK-DICOM.

Users of these products are advised to ensure their systems are updated with the latest patches provided by the respective vendors. Snort coverage to detect exploitation attempts for these vulnerabilities is available through the latest rule sets from Snort.org, and additional vulnerability advisories are posted on Talos Intelligence's website.

wolfsslgeovisionvtk-dicomvulnerability disclosurepatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
phishing

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

CVE-2026-48449

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

vulnerability

Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas

Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.

breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.