Surge in Exploitation Attempts Targets Hikvision Cameras in Ukraine
Between September 21 and October 1, 2026, cybersecurity researchers observed a sharp increase in scanning and remote code execution (RCE) attempts against video surveillance devices in Ukraine. The activity primarily exploited CVE-2021-36260, a critical command injection vulnerability in unpatched Hikvision products, which allows attackers to gain control of exposed cameras without authentication.
The surge coincided with Russian missile and drone strikes, though no direct link between the cyber activity and kinetic attacks has been confirmed. Researchers at GreyNoise documented the exploitation attempts but noted that these were not confirmed takeovers of real surveillance systems.
Key Details of the Campaign
- Timeline: Reconnaissance began on September 21, with exploitation attempts spiking on September 23 and continuing through October 1, marking a nine-day surge after months of minimal activity.
- Attack Sources: Four IP addresses accounted for nearly all attempts three were PureVPN exit nodes (AS56630, Lithuania), while the fourth belonged to a Ukrainian domestic network. GreyNoise assessed that a single entity likely drove the VPN-based activity but had low confidence in linking the Ukrainian address to the same operator.
- Exploitation Method: All recorded requests used the same command test via the publicly available Nuclei template for CVE-2021-36260, indicating automated vulnerability testing rather than confirmed malware deployment or data exfiltration.
- Global vs. Targeted Activity: While increased scanning for the flaw was observed globally, the four IPs did not attempt exploitation outside Ukraine.
Vulnerability Background
CVE-2021-36260 affects Hikvision’s web server, allowing unauthenticated RCE due to poor input validation. With a CVSS score of 9.8, the flaw enables attackers to execute commands on vulnerable devices without credentials. Previous reports in 2022 identified over 80,000 exposed Hikvision cameras, though this does not reflect the current number of at-risk devices.
Potential Risks & Historical Context
Compromised surveillance cameras can expose sensitive locations and activities. In January 2024, Ukrainian authorities disabled two cameras that Russian intelligence had exploited to monitor Kyiv’s air defenses and infrastructure. While this earlier incident demonstrates the flaw’s risks, it does not confirm attribution for the latest campaign.
The observed activity highlights the persistent threat of unpatched vulnerabilities in critical infrastructure, even years after disclosure.
Source: https://cybersecuritynews.com/hikvision-camera-vulnerability-2/
Hikvision cybersecurity rating report: https://www.rankiteo.com/company/hikvision
"id": "HIK1791476727",
"linkid": "hikvision",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Surveillance and Security',
'location': 'Ukraine',
'name': 'Hikvision',
'type': 'Technology Vendor'}],
'attack_vector': 'Remote Code Execution (RCE)',
'date_detected': '2026-09-21',
'description': 'Between September 21 and October 1, 2026, cybersecurity '
'researchers observed a sharp increase in scanning and remote '
'code execution (RCE) attempts against video surveillance '
'devices in Ukraine. The activity primarily exploited '
'CVE-2021-36260, a critical command injection vulnerability in '
'unpatched Hikvision products, allowing attackers to gain '
'control of exposed cameras without authentication. The surge '
'coincided with Russian missile and drone strikes, though no '
'direct link between the cyber activity and kinetic attacks '
'has been confirmed.',
'impact': {'systems_affected': 'Video surveillance devices'},
'initial_access_broker': {'reconnaissance_period': '2026-09-21 to 2026-10-01'},
'investigation_status': 'Ongoing',
'lessons_learned': 'The observed activity highlights the persistent threat of '
'unpatched vulnerabilities in critical infrastructure, '
'even years after disclosure.',
'post_incident_analysis': {'corrective_actions': 'Patch management and '
'enhanced monitoring for '
'exploitation attempts',
'root_causes': 'Unpatched vulnerability '
'(CVE-2021-36260) in Hikvision '
'surveillance devices'},
'recommendations': 'Patch vulnerable Hikvision devices to mitigate '
'CVE-2021-36260 and monitor for exploitation attempts.',
'references': [{'source': 'GreyNoise'}],
'response': {'third_party_assistance': 'GreyNoise'},
'title': 'Surge in Exploitation Attempts Targets Hikvision Cameras in Ukraine',
'type': 'Exploitation Attempt',
'vulnerability_exploited': 'CVE-2021-36260'}