
Threat: Researchers observed exploitation attempts targeting Hikvision surveillance devices in Ukraine using CVE-2021-36260 (CVSS 9.8, Critical) during September-October 2026.
Confirmed vs. Unconfirmed: Scanning and command-execution attempts were observed. Successful compromise, data theft, and attacker attribution remain unconfirmed.
Root Cause: Improper input validation allows unauthenticated OS command injection through affected devices' web interfaces.
Immediate Action: Identify vulnerable devices, apply vendor-approved firmware updates, restrict direct WAN access, segment surveillance networks, and investigate suspicious network activity.
Security researchers have identified a surge in attempts to exploit a critical Hikvision camera vulnerability affecting network-connected surveillance equipment in Ukraine.
According to a report published by GreyNoise on October 8, 2026, the activity targeted CVE-2021-36260, a remote command execution vulnerability in certain Hikvision products. The security firm observed concentrated scanning and exploitation attempts between September 23 and October 1, following earlier reconnaissance activity.
The vulnerability is not new. Hikvision released security updates in September 2021, and the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalog in January 2022.
The renewed exploitation activity highlights an ongoing problem for organizations operating surveillance systems: older, unpatched vulnerabilities can remain relevant long after security fixes become available.
However, it is important to distinguish between attempted exploitation and confirmed compromise. GreyNoise reported command-execution tests but did not establish that the observed attempts resulted in unauthorized access to video feeds or the installation of malicious software.
This article examines what researchers observed, how the vulnerability works, and what organizations can do to assess and protect their surveillance infrastructure.
What Happened?
GreyNoise detected a concentrated increase in exploitation attempts targeting CVE-2021-36260 in Ukraine during September and October 2026.
The activity primarily involved four source IP addresses, three associated with commercial VPN infrastructure and one located on a Ukrainian network.
Researchers observed repeated command-execution tests against vulnerable Hikvision technology.
There is no confirmed public attribution for the activity, and the available findings do not establish that the attempts resulted in successful device compromise.
Organizations using affected Hikvision equipment should verify firmware versions, restrict management interfaces from the public internet, and investigate suspicious network activity.
Hikvision Vulnerability: Key Facts
|
Category |
Details |
|
Vulnerability |
CVE-2021-36260 |
|
Manufacturer |
Hikvision |
|
Vulnerability type |
OS command injection |
|
Weakness classification |
CWE-78 |
|
CVSS v3.1 severity |
9.8, Critical |
|
Attack vector |
Network |
|
Attack complexity |
Low |
|
Authentication required |
No |
|
User interaction required |
No |
|
Potential security impact |
High confidentiality, integrity, and availability impact |
|
Vulnerability disclosure |
September 2021 |
|
CISA Known Exploited Vulnerabilities listing |
January 10, 2022 |
|
Newly reported activity |
September 23 to October 1, 2026 |
|
New research report |
October 8, 2026 |
|
Security updates |
Available for affected products |
|
Confirmed outcome of the new attempts |
Not established in the public GreyNoise summary |
The vulnerability classification and severity information come from the National Vulnerability Database. The 2026 activity details come from GreyNoise.
What Researchers Discovered About the Hikvision Camera Attacks
GreyNoise identified a significant increase in suspicious traffic targeting surveillance equipment in Ukraine.
The activity involved scanning and attempted exploitation associated with CVE-2021-36260.
Researchers reported that comparable activity targeting Ukraine had been rare during the preceding months. Beginning September 23, however, exploitation attempts increased sharply.
A Concentrated Nine-Day Surge
The new activity was concentrated within a relatively short period.
GreyNoise identified four IP addresses responsible for almost all the recorded exploitation attempts in its relevant observations.
Three were commercial VPN exit nodes associated with PureVPN infrastructure in Lithuania. The fourth originated from a domestic Ukrainian network.
GreyNoise assessed that the activity from the three VPN exit nodes was attributable to one entity. The relationship between those addresses and the Ukrainian source was assessed with low confidence.
The researchers also observed a broader global increase in scanning and exploitation attempts involving the same vulnerability.
However, those four source IP addresses did not target GreyNoise sensors outside Ukraine during the observed campaign.
Timeline of the September and October 2026 Activity
|
Date |
Observed activity |
|
September 21 |
A Ukrainian source IP initiated connection attempts to service ports without an observed exploit |
|
September 22 |
Comparable exploitation activity remained very limited |
|
September 23 |
A sharp increase in CVE-2021-36260 exploitation attempts began |
|
September 27 |
Repeated command-execution tests continued |
|
October 1 |
The last attempts from the four identified addresses were recorded |
|
October 7 |
GreyNoise reported no further attempts from those addresses since October 1 |
|
October 8 |
GreyNoise published its findings |
The dates describe the activity observed through GreyNoise's monitoring infrastructure. They should not be interpreted as a complete record of every attack against Hikvision devices during this period.
Why Ukraine Was a Particularly Sensitive Target
The exploitation attempts occurred while Ukraine was experiencing continued Russian missile and drone strikes.
Compromised surveillance systems could potentially expose information about sensitive facilities, movements, and operational activity.
Such information may be valuable in conflict environments where physical reconnaissance has direct security implications.
However, these are potential risks rather than confirmed outcomes of the October 2026 findings.
GreyNoise explicitly stated that it could not establish whether the observed cyber activity was connected to the physical strikes.
No particular threat actor or government has been conclusively identified as responsible for these exploitation attempts.
Key takeaway: The timing and geographic concentration make the activity significant, but they do not prove its motive or attribution.
What is CVE-2021-36260?
CVE-2021-36260 is a critical operating system command injection vulnerability affecting the web server component of certain Hikvision products.
The flaw results from insufficient input validation.
In affected systems, specially crafted network requests can potentially cause the device to execute commands that the remote requester should not be permitted to run.
Because exploitation does not require authentication, an attacker who can reach a vulnerable interface may attempt to exploit the weakness without possessing a valid camera account.
Understanding OS Command Injection
An operating system command injection vulnerability occurs when an application improperly handles external input and allows that input to influence commands executed by the underlying operating system.
Consider a web application that accepts configuration information from a user.
Normally, the application should validate the information and process only the permitted configuration changes.
If the application fails to separate input from operating system commands, an attacker may be able to introduce instructions that the system executes unexpectedly.
In the case of CVE-2021-36260, the affected component is the web server running on certain Hikvision devices.
The issue is classified as CWE-78, the Common Weakness Enumeration category for improper handling of special characters in operating system commands.
Why the Vulnerability is Rated Critical
NIST assigns CVE-2021-36260 a CVSS v3.1 base score of 9.8.
Its official vector is:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The vector describes a network-exploitable vulnerability with low attack complexity, no required privileges, and no required user interaction.
The high confidentiality, integrity, and availability ratings describe the potential technical impact if exploitation succeeds.
They do not mean that every exploitation attempt results in all three types of damage.
An affected device must also be reachable by the attacker. A camera isolated from untrusted networks generally presents a different exposure profile from one with a publicly accessible management interface.
How the Hikvision Remote Code Execution Attack Works
The underlying attack involves delivering specially crafted requests to a vulnerable device's web service.
If the device is affected and reachable, inadequate input validation can allow the request to trigger operating system command execution.
The vulnerability does not require the attacker to authenticate to the device first.
Technical Attack Flow
The following sequence illustrates the vulnerability's potential exploitation process.
1. Device discovery
An attacker identifies network-accessible Hikvision equipment.
Internet-exposed management interfaces create a particularly important exposure because attackers may reach them without first gaining access to the organization's internal network.
2. Vulnerability identification
The attacker attempts to determine whether the device runs firmware affected by CVE-2021-36260.
Automated vulnerability testing tools can be used to identify potentially vulnerable devices.
3. Malicious request delivery
A specially crafted request is sent to the affected web service.
The request attempts to exploit the device's insufficient input validation.
4. Command execution
If the request succeeds against a vulnerable implementation, the device may execute an unintended operating system command.
The exact results depend on the product, firmware, runtime permissions, and device configuration.
5. Potential post-exploitation activity
A successful attacker might attempt to access sensitive information, interfere with device operation, or use the compromised system as a foothold for additional activity.
These actions describe possible consequences of successful exploitation, not outcomes confirmed in the recent GreyNoise reporting.
What Happened During the Observed 2026 Attempts?
GreyNoise identified traffic associated with a publicly available Nuclei template for detecting the Hikvision remote command execution vulnerability.
Nuclei is an automated security testing framework that uses templates to identify specific classes of weaknesses.
The observed requests repeatedly attempted the same command test.
According to GreyNoise, the recorded requests from the four identified addresses did not include installation instructions for additional software.
This observation is consistent with vulnerability testing or exploitation validation.
However, the available evidence does not conclusively establish the attacker's objectives.
A vulnerability test can reveal whether a target is potentially exploitable without proceeding to malware installation.
For defenders, the distinction matters because suspicious testing activity should prompt investigation, but it should not automatically be classified as a confirmed breach.
Which Hikvision Products Are Affected?
CVE-2021-36260 affects specific Hikvision products and firmware versions that contain the vulnerable web server implementation.
It should not be assumed that every Hikvision camera, digital video recorder, or network video recorder is vulnerable.
Hikvision's original security advisory identifies affected product families and the corresponding security updates.
The correct firmware depends on the exact hardware model and installed version.
How to Check Whether a Device Is Vulnerable
Administrators should begin by identifying the products they actually operate.
Document each device's model number, firmware version, hardware revision where relevant, network address, and physical location.
Next, compare those details with Hikvision's official security advisory and firmware documentation.
The recommended process is:
- Identify the exact device model.
- Record the currently installed firmware version and build.
- Locate the corresponding product entry in Hikvision's security advisory.
- Determine whether the installed firmware falls within the affected range.
- Identify the vendor-approved fixed firmware.
- Plan and complete the update.
- Verify that the correct firmware is installed and the device operates normally.
Do not assume a firmware version is safe simply because its build date appears newer than a version mentioned for another model.
Different Hikvision product families may have different firmware branches and update requirements.
Vendor resource: Hikvision's CVE-2021-36260 security advisory.
Organizations managing large camera deployments can also benefit from an IoT and embedded security assessment to identify vulnerable devices and evaluate their network exposure.
What Security Risks Can a Compromised Hikvision Camera Create?
Successful exploitation of a vulnerable surveillance device can create security risks extending beyond the camera itself.
The impact depends on the device's function, the privileges available to the compromised process, and the architecture of the connected network.
Unauthorized Surveillance
A compromised surveillance system may provide an attacker with opportunities to access camera functions or information that should remain restricted.
Depending on the device and access obtained, the attacker could potentially expose sensitive physical locations or operational activities.
However, the existence of CVE-2021-36260 does not establish that attackers accessed any particular video feed during the reported campaign.
Surveillance System Disruption
A compromised device may be vulnerable to interference with its normal operation.
Potential consequences include interrupted recording, unavailable camera functions, or disruption to connected surveillance infrastructure.
For organizations that depend on video monitoring for physical security, availability can be as important as confidentiality.
Internal Network Exposure
Many organizations connect surveillance equipment to larger corporate networks.
A compromised camera or recorder could become a potential starting point for further network activity if segmentation and access controls are weak.
This does not mean CVE-2021-36260 automatically provides access to other systems.
Additional access paths, permissions, or weaknesses would be required.
Organizations should evaluate whether surveillance devices can reach internal servers, administrative systems, cloud-connected services, or other sensitive resources.
A properly designed internal network security assessment can help identify unnecessary communication paths.
Operational and Business Consequences
The potential consequences differ by environment.
A retail organization may be concerned about surveillance availability and customer privacy.
A manufacturing facility may depend on camera coverage for monitoring restricted production areas.
A hospital may need to protect cameras installed in sensitive locations.
Government and critical infrastructure operators may have additional concerns about physical security information.
Risk assessments should consider the importance of each surveillance system rather than treating every camera as equally critical.
How Security Teams Can Detect Exploitation Attempts
Detecting exploitation attempts against surveillance systems requires visibility into network traffic, device configuration, and management activity.
Many embedded devices offer fewer security monitoring capabilities than traditional servers or employee workstations.
As a result, network-level monitoring is particularly valuable.
1. Review Firewall and Network Logs
Identify inbound traffic reaching the web management interfaces of Hikvision devices.
Look for unexpected external connections, repeated requests, and unusual request patterns.
Where available, inspect HTTP request telemetry for behavior consistent with published vulnerability detection signatures.
A suspicious connection alone does not establish that exploitation succeeded.
2. Review the Published Source IP Addresses
GreyNoise identified these VPN-associated source addresses in the observed activity:
|
IP address |
Reported context |
|
195.238.124.178 |
Commercial VPN exit infrastructure |
|
195.238.124.181 |
Commercial VPN exit infrastructure |
|
195.238.124.188 |
Commercial VPN exit infrastructure |
These addresses were associated with AS56630 in Lithuania during the reported activity.
Because commercial VPN addresses may be shared by unrelated users, an IP match does not independently prove malicious intent or identify an attacker.
Security teams can search historical firewall and network logs for connections involving these addresses, particularly during the reported period.
Any findings should be evaluated alongside request behavior, device exposure, and other security evidence.
The fourth Ukrainian IP address was not publicly identified in the GreyNoise summary.
3. Monitor Unexpected Outbound Traffic
Surveillance devices generally have defined communication requirements.
Organizations should establish which management systems, recording servers, DNS services, time servers, and approved remote services each device needs to contact.
Unexpected outbound connections should receive additional scrutiny.
Particular attention should be given to unexplained communication with unfamiliar external infrastructure.
However, unusual traffic is an investigative signal rather than conclusive proof of exploitation.
4. Investigate Device Configuration Changes
Check for unauthorized changes involving:
- Administrative settings
- Network configurations
- Remote-access services
- User accounts
- Recording configurations
- Firmware versions
- Device availability
Configuration changes may result from legitimate maintenance, so investigators should compare them with approved operational activities.
5. Correlate Multiple Security Signals
A stronger investigation combines evidence from several sources.
For example, a suspicious HTTP request becomes more significant if it is followed by an unexplained configuration change or unexpected outbound connection from the same device.
MITRE ATT&CK technique T1190, Exploit Public-Facing Application, provides a useful framework for understanding attempts to exploit externally reachable management services.
Technique T1059.004, Unix Shell, may be relevant to subsequent command execution when supporting evidence exists.
These are analytical mappings, not a claim that GreyNoise confirmed every stage of an intrusion.
Organizations requiring broader monitoring can incorporate relevant findings into their cyber threat intelligence processes.
How to Protect Hikvision Cameras Against CVE-2021-36260
The most important corrective action is to apply the appropriate Hikvision security update to affected devices.
CISA has recommended updating vulnerable Hikvision products using the vendor's guidance.
However, firmware updates should be supported by exposure reduction, network segmentation, monitoring, and appropriate incident response procedures.
Immediate Security Actions
Identify affected equipment.
Inventory all relevant cameras, NVRs, and other Hikvision products.
Check firmware versions.
Compare installed versions with the applicable vendor advisory.
Review internet exposure.
Identify devices with directly reachable web administration interfaces.
Restrict unnecessary remote access.
Remove public access to administrative interfaces wherever practical.
Investigate suspicious activity.
Review available network and device records before assuming an exposed system is uncompromised.
Apply the Appropriate Firmware Updates
Hikvision released security updates addressing CVE-2021-36260 in 2021.
Administrators should obtain firmware only from authorized vendor resources and ensure it matches the exact device model.
Before updating critical surveillance systems, review the vendor's instructions and prepare for operational interruptions.
Where practical, document configurations and create supported backups.
After installation, verify the firmware version and confirm that recording, monitoring, and management functions continue working.
Firmware updates should not be treated as proof that a previously compromised device is clean.
If compromise is suspected, incident response procedures should determine whether evidence must be preserved before rebooting or reinstalling software.
Restrict Direct Internet Access
A camera management interface exposed directly to the internet can be reached by anyone who can connect to that service.
If the device is vulnerable, this increases the opportunity for remote exploitation.
Hikvision's published security guidance identifies direct WAN access and unnecessary port forwarding as significant exposure concerns.
A more controlled design restricts management traffic to approved networks and authorized administrators.
Where remote administration is necessary, organizations can use appropriately secured remote-access infrastructure instead of exposing camera interfaces publicly.
An attack surface management program can help organizations discover surveillance equipment that has unintentionally become internet accessible.
Separate Surveillance Networks
Network segmentation reduces the ability of one compromised device to communicate freely with other systems.
Cameras and recorders should be placed in dedicated network segments where operationally practical.
Firewall rules should permit only required communication between surveillance devices and approved management systems.
Administrative access should be limited to authorized personnel.
This approach can reduce the potential consequences of device compromise even when an unknown vulnerability remains.
Strengthen Administrative Access
Strong passwords, appropriate access controls, and regular account reviews remain important.
However, changing a password does not fix CVE-2021-36260 because the vulnerability can be exploited without authentication.
Organizations should distinguish between controls that prevent unauthorized login and controls that address vulnerabilities in the underlying software.
Both are necessary, but they solve different problems.
Comparing Security Controls for Hikvision Vulnerabilities
|
Security control |
Main purpose |
Fixes CVE-2021-36260? |
|
Vendor firmware update |
Corrects the vulnerable implementation |
Yes, when the appropriate fixed firmware is installed |
|
Strong administrative password |
Reduces unauthorized account access |
No |
|
Restricted management interface |
Limits who can reach the vulnerable service |
No, but reduces exposure |
|
Network segmentation |
Limits communication between device groups |
No, but can reduce impact |
|
Firewall filtering |
Restricts unwanted connections |
No, but can reduce reachable attack paths |
|
Network monitoring |
Helps identify suspicious activity |
No |
|
Vulnerability assessment |
Identifies affected or exposed systems |
No |
|
Incident response |
Investigates and contains possible compromise |
No |
The comparison shows why a defense-in-depth approach is preferable to relying on a single security setting.
Key takeaway: Firmware remediation addresses the underlying vulnerability, while network controls reduce opportunities for exploitation and help contain potential damage.
What Organizations Should Do If They Suspect a Camera Was Compromised
When exploitation is suspected, organizations should treat the situation as a possible security incident.
The immediate objective is to determine whether the device was exposed, whether suspicious activity reached it, and whether there is evidence of unauthorized access.
Preserve Relevant Evidence
Collect available firewall logs, network traffic records, device configuration information, and administrative activity records.
Document when the suspicious activity occurred and which assets were involved.
Avoid unnecessary actions that could overwrite useful evidence before investigators have assessed the situation.
Contain the Possible Exposure
Restrict the affected device's communication with untrusted networks.
Depending on operational requirements, this may involve temporarily disabling remote management access or isolating the device's network segment.
Physical security requirements should be considered before disconnecting a critical surveillance system.
Investigate Related Systems
Determine whether the device could communicate with recording servers, management workstations, or sensitive internal infrastructure.
Review those systems for relevant suspicious activity.
If evidence suggests broader unauthorized access, expand the investigation accordingly.
Recover and Validate
After the investigation and appropriate evidence preservation, restore affected systems to a trusted state using vendor-supported procedures.
Apply corrected firmware and review security configurations.
Confirm that unnecessary access paths have been closed.
For complex investigations, digital forensic investigation and incident response and recovery planning can support a structured response.
Expert Insight: Why Old Camera Vulnerabilities Remain Operationally Important
The October 2026 activity illustrates a practical weakness in how some organizations manage embedded and physical security systems.
A vulnerability does not become harmless simply because the manufacturer released a patch years earlier.
The risk remains relevant wherever vulnerable products continue operating.
Surveillance infrastructure can also fall between administrative responsibilities.
Physical security teams may manage camera placement and recording operations, while IT teams manage network controls and cybersecurity monitoring.
If responsibilities are unclear, firmware updates, device inventories, and security alerts may receive inconsistent attention.
The operational lesson is to treat cameras and recording appliances as managed computing assets.
They require clear ownership, documented software versions, restricted access, and defined incident response procedures.
Organizations should include this equipment in their regular vulnerability management activities rather than excluding it because it is primarily used for physical security.
Common Security Mistakes to Avoid
Several security practices can leave surveillance infrastructure unnecessarily exposed.
Assuming old vulnerabilities are no longer exploited
An older disclosure date does not mean attackers have stopped targeting vulnerable systems.
CVE-2021-36260 was disclosed in 2021, yet GreyNoise observed renewed exploitation attempts in 2026.
Exposing camera administration interfaces to the public internet
Direct access makes vulnerable interfaces reachable from untrusted networks.
Restrict management access wherever possible.
Treating password changes as a complete fix
Authentication improvements do not correct an unauthenticated command injection flaw.
Affected firmware still needs to be updated.
Assuming all Hikvision devices have identical firmware requirements
Firmware branches and fixes can vary by product.
Always verify the exact model and vendor-supported update.
Relying only on individual IP blocklists
Blocking an observed source address may be useful in a specific environment, but addresses can change or be shared.
The more durable controls are firmware remediation, restricted access, segmentation, and behavioral monitoring.
Ignoring surveillance devices during security assessments
Cameras and recording appliances are network-connected systems with their own attack surfaces.
They should be included in asset management and security review processes.
Frequently Asked Questions
1. What is the Hikvision camera vulnerability CVE-2021-36260?
CVE-2021-36260 is a critical command injection vulnerability affecting the web server in certain Hikvision products.
It can allow a remote attacker with network access to an affected service to attempt unauthorized command execution without authentication.
2. Is CVE-2021-36260 actively exploited?
Yes. CISA included the vulnerability in its Known Exploited Vulnerabilities catalog in January 2022.
GreyNoise also reported renewed exploitation attempts targeting Ukraine in September and October 2026.
The new observations do not establish that the specific attempts resulted in successful compromises.
3. Can attackers exploit the vulnerability without a password?
Yes.
The CVSS assessment indicates that exploitation does not require authentication.
However, the attacker must be able to reach the affected service.
4. Are all Hikvision cameras vulnerable?
No.
The vulnerability affects specific product and firmware combinations.
Administrators should consult Hikvision's official security advisory to determine whether a particular device requires an update.
5. Does updating firmware fix the vulnerability?
Hikvision released firmware updates addressing CVE-2021-36260.
Installing the correct fixed firmware addresses the documented vulnerability.
The update should be verified against the device's exact model and version.
6. Does changing the camera password prevent CVE-2021-36260?
No.
Strong passwords protect authentication, but they do not remediate this unauthenticated command injection vulnerability.
Firmware updates and network exposure controls are required.
7. Were Ukrainian Hikvision cameras successfully compromised in October 2026?
The publicly available GreyNoise summary documents scanning and exploitation attempts.
It does not confirm that the specific observed requests resulted in successful device takeovers or malicious software installation.
8. Are the attacks linked to Russia?
The activity occurred during a period of Russian military strikes against Ukraine.
However, GreyNoise did not establish a direct relationship between the exploitation attempts and those military operations.
The attacker responsible for the observed activity has not been conclusively identified.
9. What should organizations check first?
Organizations should identify Hikvision devices, verify their firmware versions, and determine whether management interfaces are exposed to untrusted networks.
Security teams should also review relevant logs and investigate evidence of suspicious activity.
Key Takeaways
The renewed attempts to exploit Hikvision camera vulnerability CVE-2021-36260 demonstrate why known security weaknesses must remain part of ongoing vulnerability management.
The most important findings are:
- GreyNoise observed a concentrated increase in exploitation attempts targeting surveillance equipment in Ukraine between September 23 and October 1, 2026.
- The activity involved CVE-2021-36260, a critical vulnerability with a CVSS v3.1 score of 9.8.
- The identified traffic primarily originated from four IP addresses, including three commercial VPN exit nodes.
- The publicly available evidence does not confirm successful device compromises or establish responsibility for the activity.
- Security updates have been available since 2021, making firmware verification and exposure reduction important defensive priorities.
Wrap Up
The latest Hikvision camera vulnerability activity is a reminder that previously disclosed flaws can continue to attract attackers years after patches become available.
GreyNoise's findings provide evidence of a focused increase in exploitation attempts against Ukrainian surveillance infrastructure. They do not, however, establish that the activity resulted in successful compromises or confirm who was responsible.
For organizations operating Hikvision surveillance equipment, the priority is to determine whether affected firmware remains in use and whether vulnerable management services are accessible from untrusted networks.
Maintaining accurate device inventories, applying vendor-approved updates, restricting remote access, and monitoring suspicious network activity can help reduce exposure.
Organizations that need a broader view of device and network risks can begin with a structured cybersecurity assessment covering surveillance equipment alongside their other connected infrastructure.
The important goal is not simply to respond to the latest headline, but to maintain the processes needed to identify and address similar weaknesses before they become incidents.
References
1. GreyNoise Intelligence
Spike in Attacks Targeting Digital Video Recorders in Ukraine.
Published October 8, 2026.
2. National Institute of Standards and Technology
National Vulnerability Database: CVE-2021-36260.
3. Cybersecurity and Infrastructure Security Agency
Remote Code Execution Vulnerability in Hikvision Cameras.
Published September 28, 2021.
4. Hikvision Security Response Center
Security Notification: Command Injection Vulnerability in Some Hikvision Products.
Advisory HSRC-202109-01.
View the Hikvision security advisory
This article reflects publicly available information reviewed on October 9, 2026. The reported exploitation activity, attribution,affected product information, and security guidance should be reassessed when new vendor advisories or threat intelligence become available.



-20260925120840.webp&w=3840&q=75)

-20260918120903.webp&w=3840&q=75)