Threat reportVulnerabilityTL-2026-3050

Spike in CVE-2021-36260 Exploitation Attempts Against Hikvision DVR/NVR Devices in Ukraine

highACTIVE

Spike in CVE-2021-36260 Exploitation Attempts Against (TL-2026-3050) is a high-severity software vulnerability scored CVSS 9.8, first published 2026-10-08. It has no confirmed attribution, affects Hikvision IP cameras, PTZ cameras and NVRs with the affected web, references 1 CVE (CVE-2021-36260), maps to 6 MITRE ATT&CK techniques (T1059.004, T1090, T1190), and is covered by 9 detection rules and 11 indicators of compromise.

CVSS
9.8/10High
CVEs
1Referenced vulnerabilities
Techniques
6MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
11Indicators of compromise

Key facts for TL-2026-3050

Threat ID
TL-2026-3050
Severity
HIGH
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, critical-infrastructure, physical-security, surveillance
Target regions
ukraine
Detection rules
9
Indicators of compromise
11

Malware and tooling in Spike in CVE-2021-36260 Exploitation Attempts Against

Malware and tooling: MooBot, nuclei

How Spike in CVE-2021-36260 Exploitation Attempts Against works

GreyNoise observed a nine-day surge (Sep 23 - Oct 1, 2026) of CVE-2021-36260 command-injection attempts against Hikvision IP camera/NVR devices in Ukraine, sent almost entirely by four IPs (three PureVPN-associated exit nodes on AS56630 in Lithuania, plus one Ukrainian domestic IP with low-confidence linkage) using the projectdiscovery nuclei template. Every recorded request from the four IPs was the same command test and nothing was installed. No actor is named.

GreyNoise reports a surge of exploitation attempts against Hikvision IP camera and NVR products in Ukraine between 21 September and 1 October 2026 (UTC), tagged 'Hikvision IP Camera RCE CVE-2021-36260 Attempt'. Attempts against Ukraine had been rare since early July and there was almost nothing on 22 September. On 23 September attempts jumped from near zero, with four IPs sending almost all of them. Three of the IPs (195.238.124.178, 195.238.124.181, 195.238.124.188) are commercial VPN exit nodes on AS56630 in Lithuania associated with PureVPN, and GreyNoise assesses that activity as attributable to a single entity. The fourth is an unnamed Ukrainian domestic IP that on 21 September sent connection attempts to service ports in Ukraine with no exploit; GreyNoise rates its link to the other three as low confidence. The four IPs made no exploitation attempts against GreyNoise sensors outside Ukraine, and none were seen from any of them after 1 October (checked to 7 October). Every recorded request from the four IPs was the same command test, with nothing to install. GreyNoise matched the traffic to the public projectdiscovery nuclei template 'Hikvision IP camera/NVR - Remote Command Execution'.

CVE-2021-36260 is an unauthenticated OS command injection (CWE-78) in the web server of many Hikvision products, rated CVSS 3.1 9.8. It needs only network access to the device's HTTP(S) port, with no credentials or user interaction. The researcher WatchfulIP found it on 20 June 2021 and said it dates back to at least 2016. Hikvision and the researcher published advisories on 18 September 2021, and NVD published the CVE on 2021-09-22. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-10. The public nuclei template exercises it with two requests: a PUT to /SDK/webLanguage carrying an XML body whose <language> element contains a $(echo <random-12-char-string>>webLib/x) command substitution, then a GET of /x to read the string back. A response containing the random string confirms command execution on the device. This is a harmless proof-of-execution check, and the same vulnerability has been used for botnet recruitment, notably by the Mirai-based Moobot in December 2021.

GreyNoise notes that the surge coincided with escalated Russian missile and drone strikes on Ukraine but states it cannot say whether the two are connected. The possible motive (battlespace awareness through compromised cameras) is unconfirmed speculation. GreyNoise also records a separate global rise in CVE-2021-36260 detections that did not come from these four IPs. The source gives no request counts, JA3/JA4 fingerprints, user agents, firmware versions, malware, hashes, domains or mitigations. Because PureVPN is a commercial service, the egress IPs may be shared with other users.

MITRE ATT&CK techniques used in TL-2026-3050

Execution

T1059.004 Unix Shell

Command and Control

T1090 Proxy

Initial Access

T1190 Exploit Public-Facing Application

Resource Development

T1588.002 Tool

Reconnaissance

T1595.001 Scanning IP Blocks; T1595.002 Vulnerability Scanning

Affected products and versions in Spike in CVE-2021-36260 Exploitation Attempts Against

  • Hikvision — IP cameras, PTZ cameras and NVRs with the affected web server (e.g. IPC_E0/E2/E6/E7, IPC_G3/G5, IPC_H1/H5/H8, IPC_R2, IPD_E7/G3/H5/H7/H8; legacy IPC_R7, IPD_R7, IPC_G0, IPC_H3, IPD_H3 up to 5.4.x)
    Vulnerable versions: Firmware released before the September 2021 security updates; dates back to at least 2016
    Fixed in: Hikvision September 2021 security firmware, e.g. V5.5.800 build 210628 for IPC_G3 and IPC_H5

Remediation for Spike in CVE-2021-36260 Exploitation Attempts Against

Patches

  • Apply Hikvision's September 2021 security firmware for affected models (for example IPC_G3 and IPC_H5 V5.5.800 build 210628)

Immediate actions

  • Identify Hikvision IP cameras/NVRs reachable from the internet and remove direct exposure of their HTTP(S) management ports
  • Block or alert on inbound PUT requests to /SDK/webLanguage and GET requests to /x on camera web servers
  • Review device logs and web root for an unexpected file at webLib/x (the nuclei check writes one)

Workarounds

  • Restrict access to the camera web server by source IP at the perimeter
  • Do not expose cameras via port forwarding or UPnP

Longer-term hardening

  • Place cameras/NVRs behind VPN or an allowlisted management network segment
  • Track vendor firmware for all deployed Hikvision models and retire end-of-life units
  • Monitor outbound connections from camera VLANs for unexpected destinations

CVEs associated with Spike in CVE-2021-36260 Exploitation Attempts Against

CVE-2021-36260

Weaknesses (CWE) in Spike in CVE-2021-36260 Exploitation Attempts Against

CWE-78

Timeline of Spike in CVE-2021-36260 Exploitation Attempts Against

  • Researcher WatchfulIP discovers the Hikvision web-server command injection later assigned CVE-2021-36260; the flaw dates back to at least 2016.
  • Hikvision and WatchfulIP publish their respective advisories; patched firmware (e.g. IPC_G3/IPC_H5 V5.5.800 build 210628) confirmed to fix the issue.
  • NVD publishes CVE-2021-36260 with CVSS 3.1 base score 9.8 (CWE-78).
  • CISA adds CVE-2021-36260 to the Known Exploited Vulnerabilities catalog (due date 2022-01-24); the vulnerability had also been used by the Mirai-based Moobot botnet in December 2021.
  • A Ukrainian-network IP (low-confidence link to the others) sends connection attempts to service ports in Ukraine with no exploit.
  • Almost no CVE-2021-36260 attempts against Ukraine, as has been the case since early July; none from the four IPs.
  • Exploitation attempts against Ukraine jump from near zero; four IPs, including three PureVPN-associated AS56630 exits, send almost all of them.
  • Attempts continue, almost all from the four IPs; every recorded request is the same command test with nothing installed.
  • Last attempts recorded from the four IPs.
  • GreyNoise confirms no attempts from any of the four IPs since 1 October.
  • GreyNoise publishes its blog analysis of the Ukraine-focused Hikvision exploitation surge.

Sources cited for Spike in CVE-2021-36260 Exploitation Attempts Against

Detection coverage for TL-2026-3050

As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3050 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
11 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats