// AI threat desk · 9 Oct 2026
Home/CVE · Vulns & Patches
Vulns & PatchesCriticalCVECVSS 9.8

Scanning and RCE attempts on video-surveillance devices rose in Ukraine

HKCERT reported increased scanning and remote-code-execution attempts targeting video-surveillance devices in Ukraine between Sep 21 and Oct 1.

AI-generated image of analysts monitoring surveillance-camera feeds and cybersecurity alerts in a dim operations centre.
AI-generated image, not a photo of the event.
Key takeaways
  • HKCERT reported increased scanning and remote-code-execution attempts targeting video-surveillance devices in Ukraine between Sep 21 and Oct 1.
  • CVE-2021-36260 has a CVSS base score of 9.8, according to Infosecurity Magazine, and IPVM said access to the HTTP or HTTPS server port was enough.
  • IPVM reported that new firmware was available for Hikvision models confirmed to be affected.

HKCERT reported increased scanning and remote-code-execution attempts targeting video-surveillance devices in Ukraine between Sep 21 and Oct 1, 2026.

Infosecurity Magazine reported that the Hikvision vulnerability has a CVSS base score of 9.8, while IPVM said access to a device’s HTTP or HTTPS server port was enough, without a username, password or action from the camera owner.

On this page

CVE-2021-36260 needs only an HTTP or HTTPS server port

IPVM reported that only access to the HTTP or HTTPS server port was needed, with ports 80 and 443 given as typical examples. It said the camera owner did not need to initiate an action.

IPVM first reported the vulnerability on Sep 20, 2021, and said a CVE had been reserved before information was published.

Hikvision models received updated firmware

Infosecurity Magazine reported that Hikvision worked with Watchful IP to patch the command-injection vulnerability in updated firmware. It also said Hikvision told integrators to download an updated version from its website.

The affected product range includes hundreds of Hikvision models, primarily cameras, with more than 80 groupings listed by Hikvision, according to IPVM.

Moobot previously used the Hikvision flaw

BleepingComputer reported that the Mirai-based Moobot botnet was spreading by exploiting the critical command-injection flaw in the web server of many Hikvision products.

Infosecurity Magazine reported that Watchful IP discovered the vulnerability in June and that it could give threat actors complete control of compromised devices. It also said Hikvision warned that millions of cameras and network video recorders worldwide could be affected.

IPVM reported that new firmware was available for models Hikvision had confirmed as affected. HKCERT’s report was published on Oct 7, 2026.

What to do now

  1. I’d recommend you do not expose any IoT device to the Internet no matter who it is made by, Watchful IP recommended.

FAQ

What happened to Hikvision cameras in Ukraine?

HKCERT reported increased scanning and remote-code-execution attempts targeting video-surveillance devices in Ukraine between Sep 21 and Oct 1.

What is CVE-2021-36260?

It is a Hikvision vulnerability affecting hundreds of device models, primarily cameras. IPVM reported that access to the HTTP or HTTPS server port was enough, without a username or password.

What is the CVSS score for CVE-2021-36260?

Infosecurity Magazine reported that the vulnerability received a CVSS base score of 9.8 out of 10.

How was the Hikvision vulnerability patched?

Infosecurity Magazine reported that Hikvision worked with Watchful IP to patch the vulnerability in updated firmware. IPVM reported that new firmware was available for models Hikvision had confirmed as affected.

What is the Moobot connection to Hikvision?

BleepingComputer reported that the Mirai-based Moobot botnet was spreading by exploiting the command-injection flaw in many Hikvision products.

Sources

  1. Hikvision Camera Vulnerability Targeted in Remote Code Execution Exploitation Attempts, HKCERTPrimary
  2. Hikvision Has "Highest Level of Critical Vulnerability," Impacting 100+ Million Devices (Public Report), IPVMPrimary
  3. Moobot botnet spreading via Hikvision camera vulnerability, BleepingComputer
  4. Cybersecurity Vulnerability Could Affect Millions of Hikvision Cameras, Infosecurity Magazine
How we checked this story
ClaimSourceStatus
HKCERT reported increased scanning and remote-code-execution attempts targeting video-surveillance devices in Ukraine between September 21 and October 1.HKCERTConfirmed
BleepingComputer reported that the Moobot botnet was spreading by exploiting a critical command-injection flaw in many Hikvision products.BleepingComputerAttributed
Infosecurity Magazine reported that Hikvision warned customers about a vulnerability potentially affecting millions of cameras and network video recorders worldwide.Infosecurity MagazineAttributed
Watchful IP discovered the command-injection vulnerability in June and IPVM first reported it on Monday, according to Infosecurity Magazine.Infosecurity MagazineAttributed
Infosecurity Magazine reported that the vulnerability received a CVSS base score of 9.8 out of 10.Infosecurity MagazineAttributed
IPVM reported that the flaw required only access to the HTTP or HTTPS server port and no username, password or owner action.IPVMAttributed
Infosecurity Magazine reported that Hikvision worked with Watchful IP to patch the vulnerability in updated firmware.HikvisionAttributed
Infosecurity Magazine reported that Hikvision told integrators to download updated firmware to remediate the vulnerability.Infosecurity MagazineAttributed
IPVM reported that CVE-2021-36260 had been reserved for the vulnerability before information was published.IPVMAttributed
IPVM reported that the vulnerability affected hundreds of Hikvision device models, primarily cameras.IPVMAttributed
IPVM reported that new firmware fixing the vulnerability was available for confirmed affected Hikvision models.IPVMAttributed
HKCERT published its report on Oct 7, 2026.HKCERTConfirmed
ipvm.com published its report on Sep 20, 2021.ipvm.comConfirmed

Could not verify

  • Whether the 2026 exploitation attempts involved CVE-2021-36260 is not established.
  • How many Hikvision devices were affected in Ukraine is not established.
  • Whether Moobot exploited the vulnerability in Ukraine is not established.
  • Whether all affected products had received firmware fixes is not established.
Explore with AI