GreyNoise: nine-day surge in attempts to exploit the old Hikvision command-injection flaw CVE-2021-36260 (CVSS 9.8) against cameras and DVRs in Ukraine, 23 Sep to 1 Oct, during heavy Russian strikes
GreyNoise reported on 8 October 2026 a rise in scanning and exploitation attempts against digital video recorders and cameras in Ukraine between 21 September and 1 October 2026. Almost all of it targeted CVE-2021-36260, the 2021 unauthenticated command injection in the web server of many Hikvision products (CVSS 9.8, NVD). Reconnaissance started on 21 September from a Ukrainian IP address; exploitation attempts jumped from near zero on 23 September and ran to 1 October. Four IP addresses sent nearly all of them: three PureVPN exit nodes (195.238.124.178, .181 and .188, AS56630) and one Ukrainian domestic address, which GreyNoise links to the VPN activity only with low confidence. Every request used the same command test from the public Nuclei template for this bug, with no payload, and the four addresses did not try it against GreyNoise sensors outside Ukraine; nothing more came from them through 7 October. GreyNoise records attempts, not confirmed takeovers, and does not link the activity to the missile and drone strikes it coincided with. Context: Ukraine said in January 2024 that Russian intelligence had used two hijacked cameras to watch Kyiv air defences. Primary: GreyNoise; wire: Cyber Security News.
- Product
- Hikvision IP cameras and NVR/DVR products (web server)
- Versions
- Unpatched Hikvision firmware affected by CVE-2021-36260 (see Hikvision's 2021 advisory for models)
- CVSS
- (NVD)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Apply Hikvision's fixed firmware for your model. Do not expose camera or recorder web interfaces to the internet, put them on a separate network segment, and block the listed VPN exit addresses if you have no reason to accept their traffic.
Primary: GreyNoise — Spike in attacks targeting digital video recorders in Ukraine (8 Oct 2026) · Vendor: CISA — RCE vulnerability in Hikvision cameras, CVE-2021-36260 (2021 alert) · CVE: CVE-2021-36260 · Cyber Security News — Hikvision camera vulnerability targeted in exploitation attempts (8 Oct 2026)
