Threat reportVulnerabilityTL-2026-3050
Spike in CVE-2021-36260 Exploitation Attempts Against Hikvision DVR/NVR Devices in Ukraine
Spike in CVE-2021-36260 Exploitation Attempts Against (TL-2026-3050) is a high-severity software vulnerability scored CVSS 9.8, first published 2026-10-08. It has no confirmed attribution, affects Hikvision IP cameras, PTZ cameras and NVRs with the affected web, references 1 CVE (CVE-2021-36260), maps to 6 MITRE ATT&CK techniques (T1059.004, T1090, T1190), and is covered by 9 detection rules and 11 indicators of compromise.
- CVSS
- 9.8/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 6MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 11Indicators of compromise
Key facts for TL-2026-3050
- Threat ID
- TL-2026-3050
- Severity
- HIGH
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, critical-infrastructure, physical-security, surveillance
- Target regions
- ukraine
- Detection rules
- 9
- Indicators of compromise
- 11
Malware and tooling in Spike in CVE-2021-36260 Exploitation Attempts Against
Malware and tooling: MooBot, nuclei
How Spike in CVE-2021-36260 Exploitation Attempts Against works
GreyNoise observed a nine-day surge (Sep 23 - Oct 1, 2026) of CVE-2021-36260 command-injection attempts against Hikvision IP camera/NVR devices in Ukraine, sent almost entirely by four IPs (three PureVPN-associated exit nodes on AS56630 in Lithuania, plus one Ukrainian domestic IP with low-confidence linkage) using the projectdiscovery nuclei template. Every recorded request from the four IPs was the same command test and nothing was installed. No actor is named.
GreyNoise reports a surge of exploitation attempts against Hikvision IP camera and NVR products in Ukraine between 21 September and 1 October 2026 (UTC), tagged 'Hikvision IP Camera RCE CVE-2021-36260 Attempt'. Attempts against Ukraine had been rare since early July and there was almost nothing on 22 September. On 23 September attempts jumped from near zero, with four IPs sending almost all of them. Three of the IPs (195.238.124.178, 195.238.124.181, 195.238.124.188) are commercial VPN exit nodes on AS56630 in Lithuania associated with PureVPN, and GreyNoise assesses that activity as attributable to a single entity. The fourth is an unnamed Ukrainian domestic IP that on 21 September sent connection attempts to service ports in Ukraine with no exploit; GreyNoise rates its link to the other three as low confidence. The four IPs made no exploitation attempts against GreyNoise sensors outside Ukraine, and none were seen from any of them after 1 October (checked to 7 October). Every recorded request from the four IPs was the same command test, with nothing to install. GreyNoise matched the traffic to the public projectdiscovery nuclei template 'Hikvision IP camera/NVR - Remote Command Execution'.
CVE-2021-36260 is an unauthenticated OS command injection (CWE-78) in the web server of many Hikvision products, rated CVSS 3.1 9.8. It needs only network access to the device's HTTP(S) port, with no credentials or user interaction. The researcher WatchfulIP found it on 20 June 2021 and said it dates back to at least 2016. Hikvision and the researcher published advisories on 18 September 2021, and NVD published the CVE on 2021-09-22. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-10. The public nuclei template exercises it with two requests: a PUT to /SDK/webLanguage carrying an XML body whose <language> element contains a $(echo <random-12-char-string>>webLib/x) command substitution, then a GET of /x to read the string back. A response containing the random string confirms command execution on the device. This is a harmless proof-of-execution check, and the same vulnerability has been used for botnet recruitment, notably by the Mirai-based Moobot in December 2021.
GreyNoise notes that the surge coincided with escalated Russian missile and drone strikes on Ukraine but states it cannot say whether the two are connected. The possible motive (battlespace awareness through compromised cameras) is unconfirmed speculation. GreyNoise also records a separate global rise in CVE-2021-36260 detections that did not come from these four IPs. The source gives no request counts, JA3/JA4 fingerprints, user agents, firmware versions, malware, hashes, domains or mitigations. Because PureVPN is a commercial service, the egress IPs may be shared with other users.
MITRE ATT&CK techniques used in TL-2026-3050
Execution
Command and Control
Initial Access
T1190 Exploit Public-Facing Application
Resource Development
Reconnaissance
T1595.001 Scanning IP Blocks; T1595.002 Vulnerability Scanning
Affected products and versions in Spike in CVE-2021-36260 Exploitation Attempts Against
- Hikvision — IP cameras, PTZ cameras and NVRs with the affected web server (e.g. IPC_E0/E2/E6/E7, IPC_G3/G5, IPC_H1/H5/H8, IPC_R2, IPD_E7/G3/H5/H7/H8; legacy IPC_R7, IPD_R7, IPC_G0, IPC_H3, IPD_H3 up to 5.4.x)
Vulnerable versions: Firmware released before the September 2021 security updates; dates back to at least 2016
Fixed in: Hikvision September 2021 security firmware, e.g. V5.5.800 build 210628 for IPC_G3 and IPC_H5
Remediation for Spike in CVE-2021-36260 Exploitation Attempts Against
Patches
- Apply Hikvision's September 2021 security firmware for affected models (for example IPC_G3 and IPC_H5 V5.5.800 build 210628)
Immediate actions
- Identify Hikvision IP cameras/NVRs reachable from the internet and remove direct exposure of their HTTP(S) management ports
- Block or alert on inbound PUT requests to /SDK/webLanguage and GET requests to /x on camera web servers
- Review device logs and web root for an unexpected file at webLib/x (the nuclei check writes one)
Workarounds
- Restrict access to the camera web server by source IP at the perimeter
- Do not expose cameras via port forwarding or UPnP
Longer-term hardening
- Place cameras/NVRs behind VPN or an allowlisted management network segment
- Track vendor firmware for all deployed Hikvision models and retire end-of-life units
- Monitor outbound connections from camera VLANs for unexpected destinations
CVEs associated with Spike in CVE-2021-36260 Exploitation Attempts Against
Weaknesses (CWE) in Spike in CVE-2021-36260 Exploitation Attempts Against
Timeline of Spike in CVE-2021-36260 Exploitation Attempts Against
- Researcher WatchfulIP discovers the Hikvision web-server command injection later assigned CVE-2021-36260; the flaw dates back to at least 2016.
- Hikvision and WatchfulIP publish their respective advisories; patched firmware (e.g. IPC_G3/IPC_H5 V5.5.800 build 210628) confirmed to fix the issue.
- NVD publishes CVE-2021-36260 with CVSS 3.1 base score 9.8 (CWE-78).
- CISA adds CVE-2021-36260 to the Known Exploited Vulnerabilities catalog (due date 2022-01-24); the vulnerability had also been used by the Mirai-based Moobot botnet in December 2021.
- A Ukrainian-network IP (low-confidence link to the others) sends connection attempts to service ports in Ukraine with no exploit.
- Almost no CVE-2021-36260 attempts against Ukraine, as has been the case since early July; none from the four IPs.
- Exploitation attempts against Ukraine jump from near zero; four IPs, including three PureVPN-associated AS56630 exits, send almost all of them.
- Attempts continue, almost all from the four IPs; every recorded request is the same command test with nothing installed.
- Last attempts recorded from the four IPs.
- GreyNoise confirms no attempts from any of the four IPs since 1 October.
- GreyNoise publishes its blog analysis of the Ukraine-focused Hikvision exploitation surge.
Sources cited for Spike in CVE-2021-36260 Exploitation Attempts Against
- Spike in Attacks Targeting Digital Video Recorders in Ukraine (GreyNoise)
- GreyNoise Timeline: Ukraine Hikvision exploitation
- NVD - CVE-2021-36260
- projectdiscovery nuclei template CVE-2021-36260
- WatchfulIP: Hikvision IP Camera Unauthenticated RCE
- CISA Known Exploited Vulnerabilities catalog (CVE-2021-36260 added 2022-01-10)
- SecurityWeek: Moobot botnet targets Hikvision devices via recent vulnerability
- ThreatDown: Thousands of Hikvision video cameras remain unpatched and vulnerable to takeover
- SentinelOne Vulnerability Database: CVE-2021-36260
- GreyNoise tag: Hikvision IP Camera RCE CVE-2021-36260 Attempt
Detection coverage for TL-2026-3050
As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3050 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.