LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-7921: Hikvision Multiple Products Improper Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 5, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 26, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-7921 to its Known Exploited Vulnerabilities catalog on Mar 5, 2026, with a federal patch deadline of Mar 26, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.

This vulnerability affects multiple Hikvision products and is caused by improper authentication. It can allow an attacker to escalate privileges and obtain access to sensitive information stored or processed by the devices. Organizations that rely on these products for surveillance or security functions should address the issue because successful exploitation can expose operational data and connected networks.

How it works

The weakness is identified as CWE-287, improper authentication. An attacker can abuse the flaw to bypass intended access controls and gain elevated privileges on the affected system.

Technical readers should note that the vulnerability class centers on missing or insufficient verification of user identity before granting higher-level access. No specific exploit mechanics are documented in the available facts, so any detailed reproduction steps must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Hikvision products are typically deployed in video surveillance, network video recording, and physical security environments. Begin by creating an inventory of all Hikvision-branded hardware and software present on your networks.

How to remediate

Apply the vendor update named in the official advisory as the primary remediation step. Follow the manufacturer’s instructions for installation and verification on each affected product.

Where cloud services are involved, implement applicable BOD 22-01 guidance. After patching, review and tighten authentication settings across the environment to reduce the chance of similar weaknesses in this product class.

If you can't patch immediately

When an immediate update is not feasible, apply compensating controls to limit exposure until remediation can be completed.

If your data may have been exposed

Actively exploited vulnerabilities of this type can result in unauthorized access to sensitive information. You can run a free exposure scan of your email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedHikvision · Multiple Products
WeaknessCWE-287
Added to CISA KEVMar 5, 2026
Federal patch deadlineMar 26, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities