CISA added two high-severity vulnerabilities affecting specific Milesight AIOT camera firmware versions, exposing the devices through embedded secrets in the product. CVE-2026-27785 is a hard-coded credentials flaw (CWE-798) that can allow unauthorized access without privileges or user interaction, with impact spanning confidentiality, integrity, and availability. The issue was listed with a CVSS v3.1 vector of AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating attackers on an adjacent network could exploit the weakness to take control of affected cameras.
CISA also published CVE-2026-32644, a hard-coded cryptographic key issue (CWE-321) tied to SSL certificates that use default private keys in Milesight camera firmware. That flaw carries a critical CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning it is remotely exploitable over the network and could enable full compromise of device communications and operations. The disclosures were accompanied by CISA advisory and CSAF references, as well as vendor firmware download links for affected Milesight products.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
ICS-CERT newly received CVE-2026-32644 on 2026-04-28 affecting specific Milesight AIOT camera firmware versions. The vulnerability involves SSL certificates using default private keys, classified as CWE-321, and is rated critical for confidentiality, integrity, and availability impact.
ICS-CERT newly received CVE-2026-27785 on 2026-04-28 for specific Milesight AIOT camera firmware versions. The flaw is a CWE-798 hard-coded credentials issue with high impact to confidentiality, integrity, and availability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.