Vendor
Hikvision vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 15 vulnerabilities in Hikvision: 0 in the last 7 days and 8 in the last 90 days, 2 of them critical and 2 exploited in the wild. The most recent, CVE-2026-85545, was published on 10 September 2026. 2 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 8
- Critical, all time
- 2
- Exploited in the wild
- 2
About Hikvision
A manufacturer of video surveillance equipment and technology solutions.
Hikvision technologies
Latest Hikvision vulnerabilities
- CVE-2026-85545: Hikvision HikCentral Access Control privilege escalationhighCVSS 7.1EPSS 0.3%
- CVE-2026-85544: Hikvision Intercom main card forgery via immutable factory valuemediumCVSS 6.1EPSS 0.4%
- CVE-2026-16843: Hikvision Wireless Access Points authenticated command executionhighCVSS 7.2
- CVE-2026-61392: Hikvision DS-2CD and DS-2DE Series information disclosuremediumCVSS 5.3
- CVE-2026-61391: Hikvision DS-2CD and DS-2DE Series stack-based buffer overflowhighCVSS 7.2
- CVE-2026-61390: Hikvision Cameras heap buffer overflow in DS-2CD and DS-2DE serieshighCVSS 7.7
- CVE-2026-57600: Hikvision Camera Series improper input validation in firmwarehighCVSS 7.5
- CVE-2026-57599: Hikvision DS-2CD Series privilege escalation in SSH interfacemediumCVSS 6.6
- CVE-2026-32684: Hikvision Application incorrect directory permissionslowCVSS 2.9EPSS 0.0%
- CVE-2026-3828: Hikvision Switches remote command execution due to insufficient input validationhighCVSS 7.2EPSS 0.8%
- CVE-2026-1749: Hikvision HikCentral Professional access control bypassmediumCVSS 6.8EPSS 0.3%
- CVE-2017-7921: Hikvision IP Cameras improper authenticationcriticalexploited in the wildCVSS 9.8EPSS 94.2%
- CVE-2025-66177: Hikvision NVR/DVR/IPC buffer overflow in Search and Discovery featurehighCVSS 8.8EPSS 0.3%
- CVE-2025-66176: Hikvision Access Control Products stack overflow in SADP XML parsinghighCVSS 8.8EPSS 0.5%
- CVE-2021-36260: Hikvision Improper Input Validationcriticalexploited in the wildCVSS 9.8
Most severe Hikvision vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2017-7921: Hikvision IP Cameras improper authenticationcriticalexploited in the wildCVSS 9.8EPSS 94.2%
- CVE-2021-36260: Hikvision Improper Input Validationcriticalexploited in the wildCVSS 9.8
- CVE-2025-66176: Hikvision Access Control Products stack overflow in SADP XML parsinghighCVSS 8.8EPSS 0.5%
- CVE-2025-66177: Hikvision NVR/DVR/IPC buffer overflow in Search and Discovery featurehighCVSS 8.8EPSS 0.3%
- CVE-2026-61390: Hikvision Cameras heap buffer overflow in DS-2CD and DS-2DE serieshighCVSS 7.7
- CVE-2026-57600: Hikvision Camera Series improper input validation in firmwarehighCVSS 7.5
- CVE-2026-3828: Hikvision Switches remote command execution due to insufficient input validationhighCVSS 7.2EPSS 0.8%
- CVE-2026-16843: Hikvision Wireless Access Points authenticated command executionhighCVSS 7.2
- CVE-2026-61391: Hikvision DS-2CD and DS-2DE Series stack-based buffer overflowhighCVSS 7.2
- CVE-2026-85545: Hikvision HikCentral Access Control privilege escalationhighCVSS 7.1EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 5 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 2 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/hikvision.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Hikvision vulnerabilities", https://junglewise.ai/threats/vendors/hikvision, 26 September 2026.