ZKTeco CCTV Camera Authentication Bypass Vulnerability (CVE-2026-8598)
CISA has issued an advisory for a critical authentication bypass vulnerability (CVSS 9.1) in ZKTeco CCTV cameras. An undocumented configuration export port accessible without authentication exposes camera credentials and service information. The affected firmware version SSC335-GC2063-Face-0b77 is deployed globally across commercial facilities. A patch (V5.0.1.2.20260421) has been released.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Medium impact. MEDIUM: Second-pass historical recalibration. This cyber advisory or vulnerability item is relevant to Cyber and technology-dependent Property/Casualty books, but it does not evidence confirmed insured loss, claims activity, ransomware/business interruption, critical infrastructure outage, or quantified market impact sufficient for HIGH.
View assessment methodologyHow we grade what we know -- Known · Reported · Uncertain. Methodology →
Timeline
Lifecycle changed
monitoring → closed
Event Closed
auto_closed_monitoring_timeout
Status changed to monitoring
Auto-transitioned: no updates for 6 hours
active → monitoring
Status changed to active
evidence_trigger: authoritative_fast_track
signal → active
Impact changed
high → medium
Initial Detection
CISA has issued an advisory for a critical authentication bypass vulnerability (CVSS 9.1) in ZKTeco CCTV cameras. An undocumented configuration export port accessible without authentication exposes camera credentials and service information. The affected firmware version SSC335-GC2063-Face-0b77 is deployed globally across commercial facilities. A patch (V5.0.1.2.20260421) has been released.
An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials.
Source: CISA Advisories (Official Advisory) · View source
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts