CVE-2026-20766

HIGHCVSS 8.8/10EPSS 0.29%

Last modified

CVE-2026-20766 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.

Description

An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS 4.0
8.6/10

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.29%

20.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
MilesightMS-Cxx63-PD<= 51.7.0.77-r12
MilesightMS-Cxx64-xPD<= 51.7.0.77-r12
MilesightMS-Cxx73-xPD<= 51.7.0.77-r12
MilesightMS-Cxx75-xxPD<= 51.7.0.77-r12
MilesightMS-Cxx83-xPD<= 51.7.0.77-r12
MilesightMS-Cxx74-PA<= 3x.8.0.3-r11
MilesightMS-C8477-HPG1<= 63.8.0.4-r3
MilesightMS-C8477-PC<= 48.8.0.4-r3
MilesightMS-C5321-FPE<= 62.8.0.4-r5
MilesightMS-Cxx72-xxxPE<= 61.8.0.5-r2
MilesightMS-Cxx62-xxxPE<= 61.8.0.5-r2
MilesightMS-Cxx52-xxxPE<= 61.8.0.5-r2
MilesightMS-Cxx66-xxxPE<= 61.8.0.5-r2
MilesightMS-Cxx66-xxxGPE<= 61.8.0.5-r2
MilesightMS-Cxx61-xxxPE<= 61.8.0.5-r2
MilesightMS-Cxx67-xxxPE<= 61.8.0.5-r2
MilesightMS-Cxx71-xxxPE<= 61.8.0.5-r2
MilesightMS-Cxx41-xxxPE<= 61.8.0.5-r2
MilesightMS-Cxx76-PE<= 61.8.0.5-r2
MilesightMS-Cxx65-PE<= 61.8.0.5-r2
MilesightMS-Cxx66-xxxG1<= 63.8.0.5-r3
MilesightMS-Cxx62-xxxG1<= 63.8.0.5-r3
MilesightMS-Cxx72-xxxG1<= 63.8.0.5-r3
MilesightMS-CQxx31-xxxG1<= CQ_63.8.0.5-r1
MilesightMS-CQxx68-xxxG1<= CQ_63.8.0.5-r1
MilesightMS-CQxx72-xxxG1<= CQ_63.8.0.5-r1
MilesightMS-Nxxxx-NxE<= 7x.9.0.19-r5
MilesightMS-Nxxxx-xxC<= 7x.9.0.19-r5
MilesightMS-Nxxxx-xxE<= 7x.9.0.19-r5
MilesightMS-Nxxxx-xxG<= 7x.9.0.19-r5
MilesightMS-Nxxxx-xxH<= 7x.9.0.19-r5
MilesightMS-Nxxxx-xxT<= 7x.9.0.19-r5
MilesightPMC8266-FPE<= PO_61.8.0.4_LPR
MilesightPMC8266-FGPE<= PO_61.8.0.4_LPR
MilesightPM3322-E<= PI_61.8.0.3_LPR-r3
MilesightTS4466-X4RIPG1<= T_63.8.0.4_LPR-r3
MilesightTS5366-X12RIPG1<= T_63.8.0.4_LPR-r3
MilesightTS8266-X4RIPG1<= T_63.8.0.4_LPR-r3
MilesightTS4466-X4RIVPG1<= T_63.8.0.4_LPR-r3
MilesightTS4466-RFIVPG1<= T_63.8.0.4_LPR-r3
MilesightTS8266-X4RIVPG1<= T_63.8.0.4_LPR-r3
MilesightTS8266-RFIVPG1<= T_63.8.0.4_LPR-r3
MilesightTS4466-X4RIWG1<= T_63.8.0.4_LPR-r3
MilesightTS8266-X4RIWG1<= T_63.8.0.4_LPR-r3
MilesightTS5510-GVH<= T_47.8.0.4_LPR-r7
MilesightTS5510-GH<= T_47.8.0.4_LPR-r6
MilesightTS5511-GVH<= T_47.8.0.4_LPR-r6
MilesightTS2966-X12TPE<= T_61.8.0.4_LPR-r3
MilesightTS4466-X4RPE<= T_61.8.0.4_LPR-r3
MilesightTS5366-X12PE<= T_61.8.0.4_LPR-r3

Showing 50 of 82 affected configurations. See the CNA advisory for the full list.

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-20766?
An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.
How severe is CVE-2026-20766?
CVE-2026-20766 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.29% probability of exploitation in the next 30 days.
How do I fix CVE-2026-20766?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-20766?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST