Hikvision Camera Vulnerability Targeted in Remote Code Execution Exploitation Attempts
GreyNoise saw exploitation attempts against Hikvision CVE-2021-36260 aimed at Ukraine, without confirmed device takeovers.
GreyNoise reported a rise in scanning and remote code execution attempts against Hikvision cameras and recorders in Ukraine from September 21 to October 1, 2026, focused on CVE-2021-36260. The critical command-injection flaw, CVSS 9.8, lets unauthenticated web requests run operating-system commands on unpatched devices. Four addresses, three PureVPN exits in Lithuania on AS56630 and one Ukrainian address, sent the same Nuclei command test with no installation payload and did not hit GreyNoise sensors outside Ukraine. Researchers did not confirm device takeovers or a link to Russian strikes; CISA still recommends firmware updates and limiting public access.