Government Advisory

Critical Flaw in Widely Used VIVOTEK Security Cameras Could Allow Full Takeover

CISA · 29 Sept 2026
Key Takeaway If your business uses VIVOTEK security cameras, check the model against CISA's advisory, isolate them from your main network, and apply firmware updates as soon as they're released.

CISA has issued an advisory covering a wide range of VIVOTEK camera models, including popular V, C, S and Dome series units commonly used for business and property surveillance. The flaw, tracked as CVE-2026-22755, could allow an attacker to remotely execute commands on the device, potentially gaining root level access and full control of the camera.

Because these cameras are often connected directly to business networks and the internet for remote monitoring, a successful attack could expose live video feeds, allow the device to be used as a foothold into the wider network, or turn it into part of a botnet. Given the large number of affected models, businesses using VIVOTEK cameras for security or CCTV purposes should check whether their devices are on the affected list and apply any vendor firmware updates as soon as they are released.

Until patches are available, businesses should ensure cameras are not directly exposed to the internet and are segmented from critical business systems.

IoT security CCTV vulnerability CISA advisory remote code execution camera security

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.