Security Digest: July 2, 2026 - 24 Critical Vulnerabilities
Today’s most urgent risk is concentrated in GeoVision GeoWebPlayer / Web Plugin / WS Player, where multiple flaws can expose screens, trigger out-of-bounds memory access, and enable remote code execution. Several high-severity WordPress plugin bugs and application-layer issues in Jenkins/PIA, MLflow, and Eclipse Parsson also require fast patching.
· 15 min read
July 2, 2026: 24 Critical Vulnerabilities Demand Immediate Action
Executive Summary
Today’s most urgent risk is concentrated in GeoVision GeoWebPlayer / Web Plugin / WS Player, where multiple flaws can expose screens, trigger out-of-bounds memory access, and enable remote code execution. Several high-severity WordPress plugin bugs and application-layer issues in Jenkins/PIA, MLflow, and Eclipse Parsson also require fast patching. Prioritize exposed GeoVision installations first, then public WordPress sites, then internal platforms with authentication enabled.
Critical Vulnerabilities
CVE-2026-13125: GeoWebPlayer unauthenticated screen capture access
- Impact: A malicious website may connect to the local websocket server and retrieve sensitive screen content.
- Affected Systems: GeoVision GeoWebPlayer / Web Plugin / WS Player used with GV-VMS, GV-Cloud, and related products.
- Immediate Action: Remove or disable the plugin where possible; restrict local websocket access; assume exposed endpoints can be abused from a browser.
- Mitigation: Apply the vendor fix as soon as available and block unauthorized localhost-to-websocket access at the host and browser policy level.
CVE-2026-13131: GeoWebPlayer connectInfo index out-of-bounds
- Impact: Memory corruption and potential crash or code execution.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Patch immediately; treat this component as unsafe until updated.
- Mitigation: Update to a fixed release and limit local access to the websocket service.
CVE-2026-13132: GeoWebPlayer setStream index out-of-bounds
- Impact: Out-of-bounds access may lead to instability or code execution.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Remove exposure from untrusted users and patch the addon.
- Mitigation: Install the vendor update and disable the service if not strictly required.
CVE-2026-57264: GeoWebPlayer setPIP index out-of-bounds
- Impact: Memory corruption from malformed local websocket commands.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Update GeoVision software and isolate affected hosts.
- Mitigation: Apply the patch and restrict local interprocess/websocket traffic.
CVE-2026-57265: GeoWebPlayer audio index out-of-bounds
- Impact: Crash or potential code execution through malformed commands.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Patch and monitor for unexpected websocket activity.
- Mitigation: Upgrade to the fixed version and disable unused audio features if possible.
CVE-2026-57266: GeoWebPlayer 2wayAudio index out-of-bounds
- Impact: Out-of-bounds memory access may destabilize the application.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Update immediately and restrict local command access.
- Mitigation: Apply vendor patches and remove the addon where not needed.
CVE-2026-57267: GeoWebPlayer snapshot index out-of-bounds
- Impact: Malformed commands may cause memory corruption.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Patch and review whether snapshot features are required.
- Mitigation: Update the component and limit local websocket access.
CVE-2026-57268: GeoWebPlayer saveVideo index out-of-bounds leading to possible code execution
- Impact: Potential code execution through out-of-bounds critical-section handling.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Treat as high priority; patch before exposing any web interface.
- Mitigation: Install the vendor fix and disable the service if it is not essential.
CVE-2026-57269: GeoWebPlayer disconnect index out-of-bounds
- Impact: Memory corruption or service crash.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Apply the update and monitor for abnormal disconnect activity.
- Mitigation: Restrict local access and patch immediately.
CVE-2026-57270: GeoWebPlayer play index out-of-bounds
- Impact: Out-of-bounds access may enable denial of service or worse.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Remove exposure from untrusted networks and patch.
- Mitigation: Upgrade to a fixed build.
CVE-2026-57271: GeoWebPlayer pause index out-of-bounds
- Impact: Crash or memory corruption.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Patch and limit service access.
- Mitigation: Apply the vendor update.
CVE-2026-57272: GeoWebPlayer byPass index out-of-bounds
- Impact: Unsafe memory access may permit code execution or bypass of expected logic.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Update immediately and review host isolation.
- Mitigation: Install the patched release and disable unused functionality.
CVE-2026-57274: GeoWebPlayer connectionInfo buffer overflow
- Impact: Remote code execution is possible through attacker-controlled JSON fields.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Patch immediately and assume compromise risk if exposed.
- Mitigation: Update to a fixed version; isolate the host and block unnecessary access.
CVE-2026-57275: GeoWebPlayer connectionInfo username buffer overflow
- Impact: Remote code execution through malformed username data.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Update now and disable the plugin if not required.
- Mitigation: Apply the vendor patch and restrict local websocket use.
CVE-2026-57276: GeoWebPlayer connectionInfo password buffer overflow
- Impact: Remote code execution through attacker-controlled password content.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Patch immediately; do not leave exposed instances online.
- Mitigation: Upgrade and remove the addon where feasible.
CVE-2026-57277: GeoWebPlayer connectionInfo key buffer overflow
- Impact: Remote code execution from oversized key fields.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Apply the fix and isolate affected systems.
- Mitigation: Patch and restrict access to the websocket service.
CVE-2026-57278: GeoWebPlayer connectionInfo ip buffer overflow
- Impact: Remote code execution through crafted IP fields.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Patch now and review exposure of any GeoVision web UI.
- Mitigation: Update to the vendor-fixed release.
CVE-2026-57273: GeoWebPlayer connectionInfo username buffer overflow without key
- Impact: Remote code execution via a second username parsing path.
- Affected Systems: GeoWebPlayer / Web Plugin / WS Player.
- Immediate Action: Treat all GeoWebPlayer instances as urgent patch candidates.
- Mitigation: Install the patched version and disable the component if possible.
CVE-2026-14336: PIA Jenkins token OIDC issuer allowlist bypass
- Impact: An attacker can force outbound requests to an attacker-controlled host and potentially mint trusted tokens.
- Affected Systems: PIA deployments using Jenkins tokens and OIDC issuer allowlisting.
- Immediate Action: Restrict
/v1/upload/sbom, review issuer validation, and patch immediately. - Mitigation: Replace prefix checks with strict URL validation and update to a fixed release.
CVE-2026-5821: WordPress Image Optimizer arbitrary file deletion
- Impact: Authenticated attackers with Author access can delete arbitrary files on the server.
- Affected Systems: Image Optimizer plugin for WordPress up to 1.7.4.
- Immediate Action: Disable the plugin or remove author-level custom field access until patched.
- Mitigation: Update to the fixed version and verify file-deletion protections.
CVE-2026-8147: MLflow trace authorization bypass
- Impact: Any authenticated user can read, modify, or delete traces outside their permissions.
- Affected Systems: MLflow prior to 3.14.0 with authentication enabled.
- Immediate Action: Patch immediately and review access to trace endpoints.
- Mitigation: Upgrade to MLflow 3.14.0 or later.
CVE-2026-9563: Eclipse Parsson unbounded JSON parsing
- Impact: Large attacker-controlled JSON can consume excessive CPU and memory, causing denial of service.
- Affected Systems: Eclipse Parsson artifacts before 1.1.8.
- Immediate Action: Upgrade dependencies and cap inbound JSON size where possible.
- Mitigation: Move to Parsson 1.1.8 or later and enable parsing limits.
CVE-2026-8441: WP Review Slider Pro SQL injection
- Impact: Unauthenticated attackers can extract data from the database via SQL injection.
- Affected Systems: WP Review Slider Pro up to 12.7.2 on public WordPress pages.
- Immediate Action: Disable the plugin or remove public access until patched.
- Mitigation: Update to the fixed version and review database exposure.
CVE-2026-9834: WP Database Backup command injection
- Impact: Authenticated administrators can execute operating system commands during backup runs.
- Affected Systems: WP Database Backup – Unlimited Database & Files Backup by Backup for WP up to 7.11.
- Immediate Action: Update immediately and audit any backup settings or scheduled jobs.
- Mitigation: Patch to the vendor-fixed release and inspect the host for suspicious commands.
What to Do Now
- Patch GeoVision first. If any GeoWebPlayer/Web Plugin/WS Player instance is present, treat it as the top priority. Remove the addon if it is not essential.
- Update public WordPress sites immediately. Prioritize plugins that can be reached by unauthenticated users or low-privilege authors.
- Upgrade MLflow, Eclipse Parsson, and PIA-related services. These affect internal platforms but can expose sensitive data or enable token abuse.
- Verify exposure. Inventory hosts for GeoVision software, affected WordPress plugins, MLflow versions, and Parsson dependencies.
- Monitor aggressively. Look for unexpected websocket connections, abnormal backup executions, SQL error spikes, and unusual outbound requests from PIA.
Verification steps: confirm version numbers, check whether the GeoWebPlayer service is running, and validate that WordPress plugins are not merely installed but active on public pages. For MLflow, confirm the deployed version is 3.14.0 or later. For Parsson, verify 1.1.8 or later in your dependency tree.
Monitoring recommendations: alert on localhost websocket access by browsers, unexpected child processes from WordPress backup jobs, suspicious OIDC discovery/JWKS lookups, and spikes in database reads tied to review-slider AJAX traffic.
Related Resources
- Internal: Link to the planned GeoVision emergency response post, WordPress plugin triage guide, and MLflow authorization review article.
- Official vendor advisories: GeoVision security bulletin, Jenkins/PIA advisory, WordPress plugin release notes, MLflow release notes, and Eclipse Parsson 1.1.8 announcement.