# Surge in Exploitation Attempts on Hikvision Cameras Triggers Security Concerns

*Published October 9, 2026*
*Source: [https://cybersecuritynews.com/hikvision-camera-vulnerability-2/](https://cybersecuritynews.com/hikvision-camera-vulnerability-2/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/surge-in-exploitation-attempts-on-hikvision-cameras-triggers-security-concerns) or [see plans](https://www.sec-news.ai/pricing).*

## Article

A significant increase in attempts to exploit a critical vulnerability in Hikvision surveillance devices has been observed in Ukraine from September 21 to October 1, 2026. This activity centers around the CVE-2021-36260 vulnerability, which allows attackers to execute commands remotely on unpatched devices without authentication. The timing of these attempts coincides with Russian missile and drone strikes in Ukraine, though researchers have not confirmed a direct link between the cyber activity and those military actions.

GreyNoise Intelligence has documented a surge in scanning and exploitation attempts, noting that these attempts do not confirm successful takeovers of surveillance systems. Initial reconnaissance began on September 21, with exploitation attempts intensifying by September 23. This activity continued for nine days, driven primarily by four IP addresses, three of which were linked to PureVPN exit nodes and one to a Ukrainian domestic network. It is believed that a single entity may be responsible for the VPN-related activity, but the link to the Ukrainian address remains uncertain.

The vulnerability in question affects the web server component of certain Hikvision products, where improper input validation allows malicious commands to reach the device's operating system. This flaw has been assigned a critical CVSS score of 9.8. Despite the widespread scanning, the observed attempts used a command test without any payload installation, suggesting that these were automated tests rather than efforts to deploy malware or access video feeds.

Hikvision cameras have previously been identified as vulnerable, with over 80,000 exposed devices reported in 2022. The potential risk of compromised cameras is significant, as they can reveal sensitive information and locations. Ukrainian authorities have previously reported disabling compromised cameras used by Russian intelligence. To mitigate these risks, administrators are advised to update firmware, restrict public access, and isolate surveillance equipment from critical networks.
