Wire Observer.
Technology

Spike in Exploit Attempts on Hikvision Cameras Detected Across Ukraine

Spike in Exploit Attempts on Hikvision Cameras Detected Across Ukraine

GreyNoise, a platform that monitors global internet noise, reported a noticeable uptick in scanning activity and remote code execution (RCE) attempts aimed at video surveillance equipment in Ukraine during the period from September 21 to October 1, 2026. The surge centered on a known critical flaw, CVE-2021-36260, which allows unauthenticated command injection on certain Hikvision devices that have not received the latest firmware updates.

The vulnerability, disclosed in 2021, remains unpatched on a sizable fleet of cameras still in operation across public institutions, transportation hubs, and private facilities. GreyNoise observed automated probes that first enumerate the presence of Hikvision hardware and then attempt to exploit the command‑injection bug to execute arbitrary code. While the data does not confirm successful compromises, the volume of attempts signals a heightened interest from threat actors in leveraging the flaw for espionage or disruptive purposes.

Ukraine’s ongoing conflict has amplified the strategic value of surveillance infrastructure, making cameras a tempting target for both state‑aligned and opportunistic groups seeking visual intelligence or a foothold within critical networks. Analysts note that compromised cameras can serve as entry points for broader network infiltration, enabling attackers to move laterally, exfiltrate data, or disrupt services. The timing of the observed activity coincides with a broader wave of cyber operations aimed at Ukrainian assets, suggesting a coordinated effort to exploit any lingering security gaps.

Hikvision, one of the world’s largest manufacturers of security equipment, has issued patches for CVE-2021-36260, but adoption has been uneven. Many organizations delay updates due to operational constraints, legacy hardware, or lack of awareness about the risk. Cybersecurity experts urge immediate remediation: applying the vendor’s firmware, isolating cameras on separate network segments, and implementing strict access controls. Some Ukrainian authorities have already issued advisories urging public and private entities to audit their surveillance deployments and verify that all devices run the latest security revisions.

Looking ahead, the surge in exploitation attempts may prompt additional defensive measures. GreyNoise expects to continue tracking the activity, while security firms anticipate that threat groups will shift tactics if the vulnerability is widely mitigated. The episode underscores the broader challenge of securing Internet‑of‑Things devices that were not originally designed with robust patch management in mind. As the situation evolves, both manufacturers and end‑users will need to prioritize timely updates and network segmentation to reduce the attack surface of critical visual monitoring systems.

Kabir Rao — Security desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related