CVE-2021-36260
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a command injection vulnerability in the web server of some Hikvision product. EPSS 100% (100th percentile).
CISA federal remediation date Jan 24 · date passed
Vulnerabilities · 23h ago
GreyNoise saw a nine-day surge of scanning and exploit attempts against Hikvision digital video recorders in Ukraine from 21 September to 1 October 2026. Almost all of the activity came from four IP addresses and lined up with an escalation in Russian strikes, though GreyNoise says it cannot confirm a direct link.
The traffic centered on CVE-2021-36260, a Hikvision flaw that allows unauthenticated command injection on unpatched products. In plain terms, an exposed recorder or camera can be reached without logging in, giving the attacker control over the device and, potentially, a live view of what that site’s feeds can see.
That makes the exposure physical as well as digital: if Hikvision gear sits on a security perimeter in a conflict zone, the compromise can support battlefield or site reconnaissance before, during, and after an attack. GreyNoise also saw the four IPs stay inside Ukraine-focused probing, which points to targeted surveillance interest rather than broad opportunistic scanning.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: a command injection vulnerability in the web server of some Hikvision product. EPSS 100% (100th percentile).
CISA federal remediation date Jan 24 · date passed
1 source covering this story
Spike in attacks targeting digital video recorders in Ukraine
For months GreyNoise recorded almost no Hikvision camera exploit attempts against Ukraine.
Part of the PlainSec briefing for 2026-10-08