Hikvision Camera Vulnerability Targeted in Remote Code Execution Exploitation Attempts
GreyNoise saw exploitation attempts against Hikvision CVE-2021-36260 aimed at Ukraine, without confirmed device takeovers.
GreyNoise reported a rise in scanning and remote code execution attempts against Hikvision cameras and recorders in Ukraine from September 21 to October 1, 2026, focused on CVE-2021-36260. The critical command-injection flaw, CVSS 9.8, lets unauthenticated web requests run operating-system commands on unpatched devices. Four addresses, three PureVPN exits in Lithuania on AS56630 and one Ukrainian address, sent the same Nuclei command test with no installation payload and did not hit GreyNoise sensors outside Ukraine. Researchers did not confirm device takeovers or a link to Russian strikes; CISA still recommends firmware updates and limiting public access.
- CVE-2021-36260 is unauthenticated command injection, CVSS 9.8
- Ukraine-focused attempts ran from September 21 to October 1, 2026
- Four IPs sent one Nuclei command test and no install payload
- No confirmed takeovers or link to Russian strikes
- Firmware updates and cutting public access are advised
Vulnerabilities mentionedAll →
- CVE-2021-362609.8100%Unauthenticated Command Injection in Hikvision Device Web Serverpublished · Hikvision Embedded web server of Hikvision security cameras and related surveillance devices KEV PoC ×3
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 195.238.124.178 | o that activity with low confidence. The VPN addresses were 195.238.124.178, 195.238.124.181, and 195.238.124.188, associated with AS56 |
| ipv4 | 195.238.124.181 | ith low confidence. The VPN addresses were 195.238.124.178, 195.238.124.181, and 195.238.124.188, associated with AS56630 in Lithuania. |
| ipv4 | 195.238.124.188 | he VPN addresses were 195.238.124.178, 195.238.124.181, and 195.238.124.188, associated with AS56630 in Lithuania. Commercial VPN exits |
Full article572 words · extracted from cybersecuritynews.com · click to collapse
GreyNoise has identified a rise in scanning and remote code execution attempts targeting video surveillance devices in Ukraine between September 21 and October 1, 2026.
Most activity focused on CVE-2021-36260, a critical command injection flaw in unpatched Hikvision products. The surge occurred alongside Russian missile and drone strikes, but researchers have not established a connection between the cyber activity and those attacks.
The findings highlight renewed interest in an older vulnerability that can let attackers control exposed cameras and recording equipment without signing in.
However, GreyNoise’s observations document exploitation attempts, not confirmed takeovers of real surveillance systems. That distinction matters when assessing the campaign’s impact and possible purpose.
Hikvision Camera Vulnerability
According to GreyNoise’s timeline, initial reconnaissance began on September 21, when an IP address on a Ukrainian network attempted connections to service ports without sending an exploit.
Exploitation attempts rose sharply on September 23 and continued through October 1, creating a nine-day surge after months of almost no comparable activity against Ukraine.
Four IP addresses accounted for almost all attempts during the surge. Three were PureVPN exit nodes, while the fourth belonged to a domestic Ukrainian network.
GreyNoise assessed that one entity drove the VPN activity, but linked the Ukrainian address to that activity with low confidence.

The VPN addresses were 195.238.124.178, 195.238.124.181, and 195.238.124.188, associated with AS56630 in Lithuania. Commercial VPN exits can serve unrelated users, so these indicators should not, by themselves, be treated as proof of a shared operator. The Ukrainian address was not publicly named.
Although GreyNoise also observed increased global scanning for the flaw, these four addresses did not attempt exploitation against its sensors outside Ukraine.
Every recorded request from the group used the same command test, with no installation payload. No further attempts from those addresses were recorded through October 7.
CVE-2021-36260 affects the web server in certain Hikvision products. Poor input checks allow crafted requests containing malicious commands to reach the device’s operating system. NIST assigns the vulnerability a critical CVSS score of 9.8, reflecting exploitation over a network without authentication or user interaction.
The observed activity used the publicly available Nuclei template titled “Hikvision IP camera/NVR – Remote Command Execution.” Its use points to automated vulnerability testing, rather than establishing that attackers installed malware or accessed video feeds. GreyNoise’s command-test observations support that narrower reading.
Cybersecurity News previously covered more than 80,000 exposed, vulnerable Hikvision cameras in 2022. That historical finding shows the flaw’s long-running exposure problem, but it is not a current count of vulnerable devices.
Compromised cameras can reveal sensitive locations and activity. In January 2024, Ukrainian authorities reported disabling two cameras that Russian intelligence had compromised to observe Kyiv’s air defenses and infrastructure. That earlier case illustrates the potential risk; it does not establish who conducted this latest campaign.
Administrators should identify affected models and apply Hikvision’s firmware updates, as CISA recommends. Restricting public access and separating surveillance equipment from critical networks can also reduce exposure while updates are arranged. Changing passwords alone does not fix an unauthenticated command injection flaw.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.