CVE-2026-20766: Milesight Ms-c2964-Rflpc
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.
Affected products
- Milesight Ms-c2964-Rflpc
- Milesight Ms-c2966-Rflwpc
- Milesight Ms-c2966-x12rlpc
- Milesight Ms-c2966-x12rlvpc
- Milesight Ms-c2972-Rflpc
- Milesight Ms-c5321-Fpe: up to and including 62.8.0.4-r5
- Milesight Ms-c5361-x12lpc
- Milesight Ms-c5366-x12lpc
- Milesight Ms-c5366-x12lvpc
- Milesight Ms-c8477-HPG1: up to and including 63.8.0.4-r3
- Milesight Ms-c8477-Pc: up to and including 48.8.0.4-r3
- Milesight Ms-CQXX31-XXXG1
- Milesight Ms-CQXX68-XXXG1
- Milesight Ms-CQXX72-XXXG1
- Milesight Ms-CXX41-Xxxpe: up to and including 61.8.0.5-r2
- Milesight Ms-CXX52-Xxxpe: up to and including 61.8.0.5-r2
- Milesight Ms-CXX61-Xxxpe: up to and including 61.8.0.5-r2
- Milesight Ms-CXX62-XXXG1: up to and including 63.8.0.5-r3
- Milesight Ms-CXX62-Xxxpe: up to and including 61.8.0.5-r2
- Milesight Ms-CXX63-Pd: up to and including 51.7.0.77-r12
- Milesight Ms-CXX64-Xpd: up to and including 51.7.0.77-r12
- Milesight Ms-CXX65-Pe: up to and including 61.8.0.5-r2
- Milesight Ms-CXX66-FIPKG1: up to and including 63.8.0.4-r1-NX
- Milesight Ms-CXX66-RFIPKG1: up to and including 63.8.0.4-r1-NX
- Milesight Ms-CXX66-XXXG1: up to and including 63.8.0.5-r3
- and 57 more
Published 2026-04-28. Last modified 2026-07-20.