Dahua published advisory DHCC-SA-202606-001 covering three vulnerabilities in IP cameras, PTZ cameras, network video recorders, and related hardware. The most serious issue, CVE-2026-29114, exposes a device CA root certificate, creating a risk of fraudulent certificate issuance where clients trust that CA. Two additional flaws enable denial of service: CVE-2026-29115 lets an authenticated remote attacker crash affected systems, while CVE-2026-29116 allows an unauthenticated attacker to send a specially crafted packet that triggers an exception and forces an unexpected reboot.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Dahua advisory DHCC-SA-202606-001 disclosed CVE-2026-29114, CVE-2026-29115, and CVE-2026-29116 affecting IP cameras, PTZ cameras, NVRs, and other hardware. The issues include certificate exposure and denial-of-service flaws, and the advisory urges customers to apply updated firmware.
NVIDIA issued a June 2026 security bulletin for NVIDIA DALI covering CVE-2026-24180 and CVE-2026-24181, warning that exploitation could lead to code execution, data tampering, denial of service, and information disclosure. NVIDIA advised users to update to or clone DALI version 2.1 or later from the GitHub repository.
A critical double-free vulnerability in strongSwan's libstrongswan component, tracked as CVE-2026-47895, was disclosed as affecting versions since 4.3.3 and potentially enabling unauthenticated remote code execution on vulnerable VPN servers. The strongSwan team released version 6.0.7 and patches for older releases to remediate the issue.
The CVE record states that CVE-2026-29116 was received by cybersecurity@dahuatech.com on June 10, 2026. The flaw affects some Dahua products and allows an unauthenticated remote attacker to trigger an exception reboot, causing denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourcemitsubishielectric.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.