Vulnerabilities · 23h ago

GreyNoise sees Hikvision probing tied to Ukraine strikes

GreyNoise saw a nine-day surge of scanning and exploit attempts against Hikvision digital video recorders in Ukraine from 21 September to 1 October 2026. Almost all of the activity came from four IP addresses and lined up with an escalation in Russian strikes, though GreyNoise says it cannot confirm a direct link.

The traffic centered on CVE-2021-36260, a Hikvision flaw that allows unauthenticated command injection on unpatched products. In plain terms, an exposed recorder or camera can be reached without logging in, giving the attacker control over the device and, potentially, a live view of what that site’s feeds can see.

That makes the exposure physical as well as digital: if Hikvision gear sits on a security perimeter in a conflict zone, the compromise can support battlefield or site reconnaissance before, during, and after an attack. GreyNoise also saw the four IPs stay inside Ukraine-focused probing, which points to targeted surveillance interest rather than broad opportunistic scanning.

CVE-2021-36260

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: a command injection vulnerability in the web server of some Hikvision product. EPSS 100% (100th percentile).

CISA federal remediation date Jan 24 · date passed

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-10-08

Editions

Related stories