Hikvision CVE-2021-36260 exploit attempts surge in Ukraine
GreyNoise logged a nine-day surge of CVE-2021-36260 attempts against Hikvision devices in Ukraine, with no confirmed takeovers.
GreyNoise observed scanning and exploitation attempts against digital video recorders and Hikvision cameras and recorders in Ukraine from 21 September to 1 October 2026, after months of near-zero activity. Most attempts targeted CVE-2021-36260, an unauthenticated command-injection flaw rated CVSS 9.8, using a public Nuclei remote command-execution template for Hikvision IP cameras and NVRs. Three PureVPN exit nodes in Lithuania on AS56630 and one Ukrainian address sent the same command test with no installation payload; GreyNoise attributes the VPN activity to one entity and rates the domestic IP as possibly related. The four addresses did not hit GreyNoise sensors outside Ukraine, and activity from them stopped after 1 October. Researchers did not confirm device takeovers or connect the activity to concurrent Russian strikes. CISA continues to recommend firmware updates and limiting public access to affected devices.
- Nine-day surge of CVE-2021-36260 attempts against Hikvision devices and digital video recorders in Ukraine from 21 September to 1 October 2026, after months of near-zero activity.
- CVE-2021-36260 is an unauthenticated command-injection flaw (CVSS 9.8) that lets web requests run operating-system commands on unpatched devices.
- Attempts used a public Nuclei Hikvision IP camera/NVR remote command-execution template; the same command test was sent with no installation payload.
- Three PureVPN exit nodes in Lithuania (AS56630) and one Ukrainian address were involved; GreyNoise attributes the VPN activity to one entity and rates the domestic IP as possibly related.
- Those four IPs did not hit GreyNoise sensors outside Ukraine, and attempts from them stopped after 1 October.
- No device takeovers were confirmed, and the activity was not linked to concurrent Russian strikes.
- CISA still recommends firmware updates and limiting public access.
Coverage timelineoldest first · each row is one article
- · 23h agoSpike in Attacks Targeting Digital Video Recorders in Ukraine
GreyNoise· 62
GreyNoise recorded a nine-day surge of CVE-2021-36260 exploitation attempts against Hikvision devices in Ukraine.
- · 8h agoHikvision Camera Vulnerability Targeted in Remote Code Execution Exploitation Attempts
Cyber Security News· 67
GreyNoise saw exploitation attempts against Hikvision CVE-2021-36260 aimed at Ukraine, without confirmed device takeovers.
Vulnerabilities in this storyAll →
- CVE-2021-362609.8100%Unauthenticated Command Injection in Hikvision Device Web Serverpublished · Hikvision Embedded web server of Hikvision security cameras and related surveillance devices KEV PoC ×3
| CVE | Vulnerability | CVSS | EPSS |
|---|