A critical vulnerability in KMW CCTV cameras, tracked as CVE-2026-5386, allows unauthenticated remote attackers to reset administrator passwords and seize control of affected devices. The flaw, described as an improper password-change verification weakness and rated CVSS 9.1, affects the KM-IP521 and KM-IP421 models, including firmware versions IPCAM_V4.04.91.230307 and IPCAM_V4.04.53.210416. Successful exploitation can expose live video feeds, change device settings, disable surveillance functions, and alter logs to hide malicious activity.
KMW has released patched firmware for the affected cameras, although the update for the KM-IP421 temporarily removes cloud authorization functionality. CISA identified the issue in advisory ICSA-26-148-06 and urged organizations to treat internet-exposed cameras as a high-priority risk, particularly in sectors including government, finance, transportation, manufacturing, and commercial facilities. No active exploitation has been confirmed, but defenders were advised to apply firmware updates immediately, keep surveillance devices off the public internet, isolate them behind firewalls or segmented networks, and limit remote access to secure VPN connections.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CISA documented CVE-2026-5386 in advisory ICSA-26-148-06 and warned that the vulnerability is a high-priority risk. The advisory noted the flaw could expose video feeds, permit configuration changes, and affect surveillance operations.
Security researcher Souvik Kandar discovered CVE-2026-5386, an unverified password change flaw affecting KMW KM-IP521 and KM-IP421 CCTV devices that can allow unauthenticated remote password resets and device takeover.
KMW released firmware updates for the affected KM-IP521 and KM-IP421 devices to address CVE-2026-5386. The KM-IP421 patch temporarily removes cloud authorization functionality.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.