CISA KEV guidance for Dahua IP camera authentication-bypass flaws (CVE-2021-33044, CVE-2021-33045)
Advisory/Mitigation
Summary
Hide ▲
Show ▼
CISA kept CVE-2021-33044 and CVE-2021-33045 in the KEV catalog for Dahua IP camera authentication-bypass vulnerabilities, directing defenders to apply vendor mitigations or discontinue use if mitigations are unavailable. The guidance covers affected Dahua cameras and related products as of August 19, 2026, leaving exposed systems on notice for urgent remediation.
Cases
Related Happenings
Dahua cameras authentication-bypass vulnerabilities (multiple vulnerabilities)
Vulnerability
H score78
First: 19.08.2026 14:34
Last: 19.08.2026 14:34
Sources 1
How related:
The two 2021 flaws are authentication-bypass vulnerabilities in Dahua cameras and related products.
About this happening:
The CVE-2021-33044 and CVE-2021-33045 authentication-bypass flaws in Dahua cameras and related products remain an access risk because attackers can bypass device ident...
Dahua cameras authentication-bypass vulnerabilities (multiple vulnerabilities)
VulnerabilityHow related: The two 2021 flaws are authentication-bypass vulnerabilities in Dahua cameras and related products.
About this happening: The CVE-2021-33044 and CVE-2021-33045 authentication-bypass flaws in Dahua cameras and related products remain an access risk because attackers can bypass device ident...
Operation CameraSwarm campaign targeting Dahua devices
Campaign
H score71
First: 19.08.2026 14:34
Last: 19.08.2026 14:34
Sources 1
How related:
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique.
About this happening:
The Operation CameraSwarm campaign compromised more than 14,530 Dahua devices, creating persistent camera access and raising unauthorized surveillance risk across affected...
Operation CameraSwarm campaign targeting Dahua devices
CampaignHow related: Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique.
About this happening: The Operation CameraSwarm campaign compromised more than 14,530 Dahua devices, creating persistent camera access and raising unauthorized surveillance risk across affected...
N-able security patch release for CVE-2026-18577
Security Patch Release
H score46
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
N-able security patch release for CVE-2026-18577
Security Patch ReleaseAbout this happening: N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
Russian intelligence security camera hijacking campaign across Europe and Ukraine
Campaign
H score88
First: 20.07.2026 15:13
Last: 20.07.2026 15:13
Sources 1
About this happening:
Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, turning exposed devices into live surveillance...
Russian intelligence security camera hijacking campaign across Europe and Ukraine
CampaignAbout this happening: Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, turning exposed devices into live surveillance...
CERT/CC Tenda router backdoor mitigation
Advisory/Mitigation
H score31
First: 07.07.2026 09:40
Last: 07.07.2026 09:40
Sources 1
About this happening:
CERT/CC issued interim mitigation for Tenda firmware after disclosure of CVE-2026-11405, advising users to disable remote management and change the default LAN I...
CERT/CC Tenda router backdoor mitigation
Advisory/MitigationAbout this happening: CERT/CC issued interim mitigation for Tenda firmware after disclosure of CVE-2026-11405, advising users to disable remote management and change the default LAN I...
Timeline
-
19.08.2026 14:34 2 articles · 5h ago
CISA keeps Dahua authentication-bypass flaws in the KEV catalog
Legal Policy Action UpdateCISA kept CVE-2021-33044 and CVE-2021-33045 listed in the Known Exploited Vulnerabilities catalog for Dahua IP camera authentication-bypass vulnerabilities and directed operators of affected Dahua cameras and related products to apply vendor mitigations or discontinue use if mitigations are unavailable.
Show sources
- Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P — thehackernews.com — 19.08.2026 14:34
- Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P — thehackernews.com — 19.08.2026 14:34