Skip to content
Increased Exploitation of Hikvision DVRs in Ukraine Amid Escalating Conflict

Increased Exploitation of Hikvision DVRs in Ukraine Amid Escalating Conflict

First seen 8 Oct 2026, 19:35 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 20:34 UTC
  • •CVE-2021-36260 is a critical vulnerability with a CVSS score of 9.8.
  • •Exploitation attempts surged alongside Russian military strikes in Ukraine.
  • •Activity linked to PureVPN exit nodes suggests potential coordinated attacks.

Between September 21 and October 1, 2026, a significant rise in scanning and exploitation attempts targeting Digital Video Recorders (DVRs) in Ukraine was observed, coinciding with heightened Russian military activity. The primary focus of these attacks was on CVE-2021-36260, a critical command injection vulnerability affecting unpatched Hikvision products. GreyNoise reported that the exploitation attempts involved a specific nuclei template for remote command execution. The activity was traced to three PureVPN exit nodes and one Ukrainian domestic IP address, with indications that the PureVPN-related activity may be linked to a single entity. Prior to this spike, there had been minimal activity against these systems in Ukraine. The situation remains under observation as the threat landscape evolves.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2021-09-22
CVE-2021-36260 published
A command injection vulnerability in Hikvision products was disclosed, rated CVSS 9.8.
Cybersecuritynews
2026-09-21
Spike in exploitation attempts observed
GreyNoise reported increased scanning and exploitation attempts targeting DVRs in Ukraine.
Greynoise
2026-10-01
End of observed attack surge
The heightened activity targeting Hikvision DVRs in Ukraine was noted to conclude on this date.
Cybersecuritynews

More articles in this cluster (3)

Following this threat?

Track Hikvision and CVE-2021-36260 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which devices are affected?
Unpatched Hikvision Digital Video Recorders and related surveillance products are vulnerable.
Is there confirmed exploitation in the wild?
Yes, there have been confirmed scanning and exploitation attempts targeting these devices in Ukraine.
What should organizations do to protect themselves?
Organizations should ensure that all Hikvision products are updated to the latest patches to mitigate this vulnerability.