Severity: CriticalAction: Review

VIVOTEK Camera Firmware

View CSAF Summary Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system. The following versions of VIVOTEK Camera Firmware are affected: V Series model_FD9187 (CVE-2026-22755) V Series model_FD9189 (CVE-2026-22755) V Series model_FD9365 (CVE-2026-22755) V…

Excerpt from the primary source: CISA Cybersecurity Advisories

Who is affected

Security professionals

What you should do · Review

Review whether your organization uses the affected products and assess exposure using the linked advisories.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Government advisory

VIVOTEK Camera Firmware CISA Cybersecurity Advisories · cisa.gov · Sep 29, 2026 · Primary source
Severity: HighAction: Patch

Fortra Patches Critical Vulnerabilities in BoKS

The bugs could lead to authentication bypass, shell command execution, and memory corruption.

Patch

Apply the vendor's security update for the affected products.

Severity: HighAction: PatchExploitation: Suspected

Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response

One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.

Why it matters

There are signs this may already be exploited, which usually shortens the time available to patch.

Patch

Apply the vendor's security update for the affected products.

Severity: HighAction: Patch

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances.

Patch

Apply the vendor's security update for the affected products.