Vulnerability intelligence
CVE-2026-8598
An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and exposes critical information about the camera such as open services and camera account credentials.
CVSS Score
9.1
Critical
EPSS — Exploit Probability
0.5%
Riskier than 41% of all CVEs · checked 2026-09-09
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered May 19, 2026 · latest May 19, 2026
Coverage timeline
-
ZKTeco CCTV Cameraswww.cisa.gov · May 19, 2026