Greynoise Increased Exploitation of Hikvision DVRs in Ukraine Amid Escalating Conflict
Article Content
- •CVE-2021-36260 is a critical vulnerability with a CVSS score of 9.8.
- •Exploitation attempts surged alongside Russian military strikes in Ukraine.
- •Activity linked to PureVPN exit nodes suggests potential coordinated attacks.
Between September 21 and October 1, 2026, a significant rise in scanning and exploitation attempts targeting Digital Video Recorders (DVRs) in Ukraine was observed, coinciding with heightened Russian military activity. The primary focus of these attacks was on CVE-2021-36260, a critical command injection vulnerability affecting unpatched Hikvision products. GreyNoise reported that the exploitation attempts involved a specific nuclei template for remote command execution. The activity was traced to three PureVPN exit nodes and one Ukrainian domestic IP address, with indications that the PureVPN-related activity may be linked to a single entity. Prior to this spike, there had been minimal activity against these systems in Ukraine. The situation remains under observation as the threat landscape evolves.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Hikvision and CVE-2021-36260 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which devices are affected?
Is there confirmed exploitation in the wild?
What should organizations do to protect themselves?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…