Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Hikvision Camera Vulnerability CVE-2021-36260 Targeted by Attackers
October 8, 2026
Fake Firefox Wallet Extensions Steal Crypto Recovery Phrases
October 8, 2026
Critical Tensorlake npm Package Flaw Spreads Shai-Hulud Worm, Steals Dev Secrets
October 8, 2026
Home/CyberSecurity News/Critical Hikvision Camera Vulnerability CVE-2021-36260 Targeted by Attackers
CyberSecurity News

Critical Hikvision Camera Vulnerability CVE-2021-36260 Targeted by Attackers

Key Takeaways A significant spike in scanning and remote code execution attempts against Hikvision video surveillance devices occurred in Ukraine between September 21 and October 1, 2026. The...

Marcus Rodriguez
Marcus Rodriguez
October 8, 2026 4 Min Read
2 0

Key Takeaways

  • A significant spike in scanning and remote code execution attempts against Hikvision video surveillance devices occurred in Ukraine between September 21 and October 1, 2026.
  • The activity specifically targeted CVE-2021-36260, a critical command injection vulnerability.
  • While the surge coincided with physical attacks, researchers have not confirmed a direct link between the cyber activity and Russian missile or drone strikes.
  • The observed activity primarily involved exploitation attempts, not confirmed system compromises or malware installations.
  • Patches are available, and immediate action is recommended for all affected Hikvision products.

Recent analysis has revealed a concentrated nine-day surge in cyberattack attempts targeting Hikvision video surveillance equipment within Ukraine. From September 21 to October 1, 2026, threat actors focused on exploiting CVE-2021-36260, a severe command injection vulnerability in unpatched devices. While this activity overlapped with Russian military actions, cybersecurity researchers have not yet established a definitive connection between the two.

Table Of Content

  • Key Takeaways
  • Hikvision Vulnerability Exploitation Surge
  • Understanding CVE-2021-36260
  • What You Should Do

This renewed interest in an older flaw underscores the persistent risk posed by unpatched systems, allowing unauthorized control over vulnerable cameras and recording devices without requiring authentication. It is crucial to note, however, that the observations document attempted exploitation, not verified breaches or system takeovers, which is an important distinction when assessing the campaign’s true impact and objectives.

Hikvision Vulnerability Exploitation Surge

According to GreyNoise’s timeline, the campaign commenced with initial reconnaissance on September 21, when an IP address within a Ukrainian network initiated connections to service ports without deploying an exploit. This preliminary scanning quickly escalated into a sharp increase in exploitation attempts beginning September 23, persisting until October 1. This nine-day burst of activity followed a period of minimal comparable cyber activity directed at Ukraine.

Nearly all attempts during this surge originated from four distinct IP addresses. Three of these were identified as PureVPN exit nodes, while the fourth was traced to a domestic Ukrainian network. GreyNoise assessed with high confidence that a single entity orchestrated the VPN-based activity, though their confidence in linking the Ukrainian IP address to the same operator was lower.

The PureVPN addresses involved were 195.238.124.178, 195.238.124.181, and 195.238.124.188, all associated with AS56630 in Lithuania. It is important to consider that commercial VPN exit nodes can be utilized by various, unrelated users, so these indicators alone do not definitively prove a shared operator. The specific Ukrainian IP address was not publicly disclosed.

Despite increased global scanning for the vulnerability, GreyNoise noted that these four specific IP addresses did not attempt exploitation against their sensors outside of Ukraine. All recorded requests from this group consistently used the same command test, lacking any installation payload. No further attempts from these addresses were observed through October 7.

Understanding CVE-2021-36260

CVE-2021-36260 is a critical command injection vulnerability affecting the web server in specific Hikvision products. The flaw stems from insufficient input validation, allowing specially crafted requests containing malicious commands to be executed directly on the device’s underlying operating system. The National Institute of Standards and Technology (NIST) assigns this vulnerability a critical CVSS score of 9.8, indicating it can be exploited over a network without authentication or user interaction.

The observed activity utilized a publicly available Nuclei template titled “Hikvision IP camera/NVR – Remote Command Execution.” This suggests that the attackers were primarily engaged in automated vulnerability testing rather than immediate malware deployment or access to video feeds. GreyNoise’s observations of command-test-only requests further support this interpretation.

Historical data from 2022 revealed over 80,000 exposed and vulnerable Hikvision cameras, highlighting the long-standing exposure issue associated with this flaw. While this past count is not a current figure, it illustrates the widespread potential impact. The compromise of surveillance cameras can expose sensitive locations and activities. For instance, in January 2024, Ukrainian authorities reported neutralizing two cameras that Russian intelligence had compromised to monitor Kyiv’s air defenses and critical infrastructure. This earlier incident underscores the severe risks associated with such vulnerabilities, though it does not establish a link to the perpetrators of this latest campaign.

What You Should Do

  • Immediately identify all Hikvision products within your network infrastructure.
  • Apply the latest firmware updates provided by Hikvision for all affected models to patch CVE-2021-36260, as CISA recommends.
  • Restrict public internet access to surveillance equipment wherever possible. Implement strong firewall rules to limit exposure.
  • Isolate surveillance systems from critical network segments to prevent lateral movement in the event of a compromise.
  • Regularly monitor network logs for unusual activity originating from or targeting Hikvision devices.
  • Note that simply changing passwords will not remediate an unauthenticated command injection vulnerability. Firmware updates are essential.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVECybersecurityExploitMalwarePatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Fake Firefox Wallet Extensions Steal Crypto Recovery Phrases

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hackers Hide C2 on Blockchain via Negative Hotel Review Malware
October 8, 2026
Critical Sungrow Inverter Vulnerability Lets Attackers Access Solar Plants
October 8, 2026
Critical LMCache Flaw (CVE-2024-XXXX) Gets PoC, Enables RCE
October 8, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us