


Perceptive Security
SOC/SIEM Consultancy

An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.
Published:
27 april 2026 om 22:00:00
Alert date:
28 april 2026 om 02:02:55
Source:
nvd.nist.gov
Mobile & IoT, Critical Infrastructure
An out-of-bounds memory access vulnerability has been identified in specific firmware versions of Milesight AIOT cameras. This vulnerability is tracked as CVE-2026-20766 and affects industrial IoT camera systems. The issue involves improper memory handling that could potentially allow attackers to access memory outside the intended boundaries. CISA has issued an advisory (ICSA-26-113-03) regarding this vulnerability. Milesight has made firmware updates available to address this security flaw. The vulnerability impacts the security of IoT camera infrastructure and could pose risks to surveillance systems.
Technical details
Mitigation steps:
Affected products:
Milesight AIOT cameras
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-20766
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-03.json
https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-03
https://www.milesight.com/support/download/firmware
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
