// 1 ZERO-DAY · 5 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
GreyNoise detects a concentrated spike of CVE-2021-36260 exploit attempts against Hikvision DVRs in Ukraine from September 21 to October 1, 2026. Unauthenticated command injection.

GreyNoise recorded a concentrated surge in exploit attempts targeting the CVE-2021-36260 vulnerability against Hikvision DVRs located in Ukraine, active from September 21 to October 1, 2026. The activity, carried out by four IP addresses geofenced exclusively to Ukrainian territory, ceased abruptly after nine days. No payload was deployed: every request consisted solely of the test command, a pattern inconsistent with monetized exploitation and indicative of systematic reconnaissance of accessible devices.

Key Takeaways
  • Nine-day spike: from September 21 to October 1, 2026, four IPs targeted sensors exclusively in Ukraine, with prior activity "near zero" since July 2026.
  • Three of the four IPs are PureVPN exit nodes in Lithuania (AS56630), assessed by GreyNoise as attributable to a single entity; the fourth is a Ukrainian residential IP, linked with low confidence.
  • CVE-2021-36260 carries a CVSS 3.1 score of 9.8 Critical and has been in the CISA KEV catalog since January 10, 2022: unauthenticated command injection in the web server of Hikvision products.
  • The absence of payloads and exclusive geofencing distinguish the operation from conventional cybercrime and align it with documented pre-kinetic reconnaissance patterns in conflict settings.

The Mechanism: Command Injection on DVRs Already in the Crosshairs for Four Years

The vulnerability CVE-2021-36260 is an unauthenticated command injection in the web server of certain Hikvision products. According to the official NVD record, the CVSS 3.1 score is 9.8 with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H: network access without authentication, low complexity, maximum impact on confidentiality, integrity, and availability. Its presence in the CISA KEV catalog since January 10, 2022 confirms a history of known active exploitation.

The actors used the public Nuclei template "Hikvision IP camera/NVR - Remote Command Execution", an automated scanning tool that lowers the technical barrier to exploitation. The choice of a public template over a proprietary exploit does not preclude sophistication; it reflects a cost-opportunity assessment where the objective is geographic coverage rather than concealment of technical origin.

The Network Signature: PureVPN, Geofencing, and Abrupt Cessation

Three of the four active IPs — 195.238.124.178, 195.238.124.181, 195.238.124.188 — belong to AS56630, identified by GreyNoise as commercial PureVPN exit nodes based in Lithuania. GreyNoise assesses this portion of activity as attributable to a single entity. The fourth address is an unnamed Ukrainian residential IP, whose connection to the three exit nodes is rated at low confidence.

The source documents exclusive geofencing: the four IPs did not attempt exploits against GreyNoise sensors outside Ukraine. Before the spike, from July 2026, attempts of this specific vulnerability against Ukraine were "near zero" and none originated from the four identified addresses. After October 1, 2026, zero attempts were recorded from the same IPs.

"The activity coincides with an escalation in Russian strikes across the country." — GreyNoise

The Absence of Payload as Significant Data

Every request logged from the four IPs contained the same test command, with no payload installation. This pattern rules out threat categories such as ransomware or cryptojacking, where the goal is immediate impact or profit. The test command verifies remote code execution without altering device state: it is the signature of pure reconnaissance, not exploitation.

The source does not specify how many or which devices in Ukraine were actually compromised. GreyNoise data reflects attempts against its own sensors, not against actual Ukrainian infrastructure. This methodological limitation is relevant: the observed activity measures intent and capability, not outcome.

Why It Matters

The dossier does not specify remedial measures related to the incident. The source does not document whether target devices were subsequently secured, nor does it provide indications of defensive actions taken by Ukrainian operators. The brief does not list additional compromised entities, lateral movement chains, or impacts on downstream systems.

What the dossier documents is the operational structure: commercial VPN exit nodes for origin masking, exclusive geofencing for geographic concentration, public template for scanning efficiency, absence of payload to minimize detection. Combined, these elements constitute a recognizable pattern even without attribution to the ultimate actor.

The temporal coincidence with the escalation of Russian strikes in Ukraine is noted by the source with explicit caution. "GreyNoise cannot say whether the two are connected": the correlation exists, causality does not. For defenders, this means response cannot rely on traditional indicators of compromise — payloads, malware, beacons — but must treat reconnaissance itself as a phase of a broader process.

Questions and Answers

Why does CVE-2021-36260, patched since 2021, remain exploitable?

The dossier does not specify the reasons for the presence of unpatched devices in Ukraine. In prolonged conflict contexts, maintenance of geographically distributed IoT systems is compromised by power outages, physical infrastructure damage, and redeployment of technical staff. The source does not document these conditions as verified causes.

Does the use of PureVPN rule out a nation-state actor?

The dossier provides no basis to exclude or confirm the actor's identity. The use of commercial VPNs is a masking technique accessible to actors of any sophistication level. GreyNoise assesses the activity from the three exit nodes as attributable to a single entity, but does not determine its nature (state, criminal, other).

Why did the activity stop on October 1?

The source does not explain the abrupt halt after nine days. Possible hypotheses — achievement of reconnaissance objectives, infrastructure change, detection — are not documented in the brief and must not be stated as facts.

Sources

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. greynoise.io
  2. nvd.nist.gov