PatchSiren cyber security CVE debrief
CVE-2026-32644 Milesight CVE debrief
CVE-2026-32644 covers Milesight AIOT camera firmware versions that use SSL certificates with default private keys. CISA published the advisory on 2026-04-23 and lists a wide set of affected camera families. The core risk is that TLS/SSL trust for impacted devices can no longer be assumed to be unique to each installation, which can undermine device identity and expose encrypted management or service traffic to impersonation risk. Milesight’s documented mitigation is to update affected devices to the latest firmware versions. Because the advisory spans many product lines and multiple version tracks, defenders should validate the exact model/firmware pairing in inventory and prioritize any internet-exposed or remotely managed cameras first.
- Vendor
- Milesight
- Product
- MS-Cxx63-PD
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-23
- Original CVE updated
- 2026-04-23
- Advisory published
- 2026-04-23
- Advisory updated
- 2026-04-23
Who should care
Security teams responsible for Milesight camera fleets, OT/physical security integrators, facilities teams, and network defenders who manage remotely accessible camera management interfaces or certificates.
Technical summary
The advisory states that specific firmware versions of Milesight AIOT cameras ship with SSL certificates that use default private keys. That means the key material is not unique per device, which weakens the security boundary normally provided by TLS certificates. CISA assigns CVSS 3.1 9.8 and SSVCv2 E:P/A:Y, indicating high urgency and likely exploitable conditions once the affected firmware is present. The vendor remediation is firmware upgrade to the fixed releases listed for each product family.
Defensive priority
High
Recommended defensive actions
- Identify all Milesight cameras and compare installed firmware against the affected versions listed in the advisory.
- Prioritize updates for internet-exposed, remotely administered, or otherwise high-trust camera deployments.
- Upgrade affected devices to the vendor-fixed firmware versions noted in the advisory.
- Confirm certificate and device identity handling after upgrading, especially for systems that pin or trust device certificates.
- Review network exposure for camera management interfaces and restrict access to trusted administrative networks.
- Document any affected models and firmware exceptions so replacement or remediation can be tracked to closure.
Evidence notes
Source corpus states: 'Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.' The advisory is CISA ICSA-26-113-03, first published 2026-04-23. The supplied remediation text says Milesight advises updating to the latest firmware from its firmware download page, and lists model-specific fixed versions for multiple product families. No KEV entry is present in the supplied data.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-32644 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-32644
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-32644 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32644
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-113-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.