CVE-2026-1185: Axis OS

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability can only be exploited if an attacker can log in to the Axis device using SSH.

Affected products

  • Axis Axis OS: from 12.0.0, before 12.10.37 (fixed in 12.10.37)

Published 2026-05-12. Last modified 2026-06-17.