VideoSOC Weekly — first issue
A standing briefing on what changed in video-infrastructure vulnerability data. Counted from the dataset on 5 September 2026, not estimated.
The standing picture
| Vulnerabilities tracked against video products | 1279 |
| Products with at least one | 3293 |
| Vendors with at least one | 69 |
| In CISA KEV — confirmed exploited | 22 |
| Published in the last 90 days | 9 |
| Records NVD re-indexed in the last 90 days | 1270 — NVD touches records in bulk, so this tracks their pipeline rather than vulnerability activity |
| Carrying no CVSS score in NVD | 0 |
Added to CISA KEV in the last year
1 video-product vulnerability was added to the Known Exploited Vulnerabilities catalogue in the twelve months to 5 September 2026. These are the only entries here backed by confirmed exploitation rather than a model.
| CVE | Added | Vendor and product, per CISA | CVSS |
|---|---|---|---|
| CVE-2017-7921 | 2026-03-05 | Hikvision Multiple Products | 9.8 |
High modelled exploitation probability, not yet in KEV
EPSS scores above 50% where CISA has not recorded confirmed exploitation. EPSS is a forecast of activity in the next 30 days, calculated 2026-09-04 — it is not an observation, and a high score is a reason to look rather than evidence that anything has happened.
| CVE | Published | Severity | EPSS | Summary |
|---|---|---|---|---|
| CVE-2022-37061 | 2022-08-18 | critical 9.8 | 99.6% | All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command… |
| CVE-2016-5674 | 2016-08-31 | critical 9.8 | 94.6% | __debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and… |
| CVE-2017-5753 | 2018-01-04 | medium 5.6 | 93.8% | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized… |
| CVE-2023-6895 | 2023-12-17 | critical 9.8 | 89.1% | A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been… |
| CVE-2019-9515 | 2019-08-13 | high 7.5 | 87.4% | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service.… |
| CVE-2018-1160 | 2018-12-20 | critical 9.8 | 86.5% | Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of… |
| CVE-2018-10661 | 2018-06-26 | critical 9.8 | 86.5% | An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access… |
| CVE-2019-9514 | 2019-08-13 | high 7.5 | 82.8% | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The… |
| CVE-2017-9828 | 2017-06-23 | critical 9.8 | 82.5% | '/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to… |
| CVE-2018-10660 | 2018-06-26 | critical 9.8 | 82.1% | An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command… |
Some rows are component vulnerabilities rather than defects in video software: CVE-2017-5753 is Spectre and CVE-2018-1160 is Netatalk, and both reach this list through the CPE record of a Synology recorder that ships them. They are in scope because they affect a video product, but the fix belongs to whoever ships the component, and a scanner that fingerprints the device as a recorder will not match either one.
Published in the last 90 days
| CVE | Published | Severity | EPSS | Summary |
|---|---|---|---|---|
| CVE-2026-75619 | 2026-08-19 | medium 6.9 | 0.2% | Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated… |
| CVE-2026-75618 | 2026-08-19 | high 7.1 | 0.2% | Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the… |
| CVE-2026-15316 | 2026-08-18 | high 7.1 | 0.2% | An improper input validation vulnerability in the configuration service for processing encrypted credential… |
| CVE-2026-15315 | 2026-08-18 | high 8.7 | 0.3% | Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication… |
| CVE-2026-13545 | 2026-06-29 | high 7.4 | 5.5% | A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file… |
| CVE-2026-12760 | 2026-06-24 | high 7.1 | 0.4% | A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling… |
| CVE-2026-12174 | 2026-06-13 | high 7.4 | 0.6% | A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function… |
| CVE-2026-6250 | 2026-06-11 | high 7.0 | 0.5% | An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper… |
| CVE-2026-11497 | 2026-06-08 | medium 5.5 | 0.4% | A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown… |
What this brief does not tell you
It counts what reached NVD. It cannot count what vendors fixed silently, what was disclosed without a CVE identifier, or what affects a product whose vendor does not participate in the CVE system — and several major video vendors do not, which is documented in the PSIRT directory. A quiet quarter in this data is not evidence of a quiet quarter in reality.