Government Advisory

Critical Flaw in ZoneMinder Video Surveillance Software Could Allow Full Server Takeover

CISA · 25 Aug 2026
Key Takeaway If your business uses ZoneMinder for CCTV or surveillance management, update to the latest patched version immediately and review who has login access to the system.

Security researchers have identified a serious vulnerability in ZoneMinder, an open-source video surveillance system used by businesses worldwide to manage security cameras. The flaw, tracked as CVE-2026-76060, is an OS command injection issue affecting ZoneMinder versions 1.37.48 and 1.38.3. It has been rated 8.8 out of 10 on the CVSS severity scale, indicating a high risk.

If exploited, an attacker who already has an authenticated account on the system could inject and run unauthorized commands on the server, potentially gaining full remote code execution as the web server user. This means an attacker could take control of the machine running the surveillance software, access sensitive data, or use it as a foothold to move further into a business's network.

While exploitation requires an existing authenticated account, businesses using ZoneMinder for physical security monitoring should treat this as a priority issue, especially if account credentials are shared, weak, or exposed. Vendors and security teams typically issue patches soon after such disclosures, so checking for updates is essential.

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.