CVE-2026-87827 affects certain KGUARD DVR devices running vulnerable firmware. NVD classifies it as CWE-1188 (Initialization of a Resource with an Insecure Default). Our source data does not carry a CVSS score for this CVE as of our ingestion. VulnCheck’s KEV feed reports the CVE as exploited, dated September 9, 2026 — though per NVD’s own record, the underlying exploitation activity dates back years earlier.
That exploitation report is single-sourced. CISA has not added CVE-2026-87827 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
Per NVD, affected KGUARD DVR devices expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to that service can execute arbitrary system commands, potentially fully compromising the device. NVD states the affected behavior traces to firmware dating from 2016; firmware released after 2017 appears to mitigate the issue by restricting the service to the localhost interface rather than exposing it on all interfaces.
NVD’s own record is unusually direct about attribution here: the vulnerability has been exploited in the wild by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets for malware propagation and subsequent DDoS activity, and this technique is documented as incorporated into versions of the RapperBot malware family. NVD states this CVE assignment exists specifically to document that active exploitation and the vendor’s lack of documentation on the issue.
Evidence and confidence
- Medium confidence — the CWE-1188 classification and the described mechanism trace to NVD alone in our current ingestion, corroborated by Netlab 360’s threat research on the Mirai_ptea botnet campaign. The exploitation report traces to VulnCheck KEV alone, though the underlying malware attribution is independently well-documented in Netlab’s public research.
- Our source data does not carry a CVSS score, vector, or EPSS score/percentile for this CVE.
No field is in conflict between our sources.
Why this matters
This is a textbook long-tail IoT botnet target: a years-old, vendor-undocumented flaw in consumer/SMB DVR hardware, quietly exploited by multiple Mirai-derivative botnet families for years before receiving a CVE identifier. The 2016-to-2017 firmware distinction NVD provides is the actionable detail — device owners cannot assume “current firmware” is safe without checking whether their specific unit predates the localhost-restriction fix, since KGUARD itself has not published clear documentation of the issue. Devices still running pre-2017 firmware on any of the affected model lines should be considered compromised-by-default if internet-exposed.
Frequently Asked Questions
What is CVE-2026-87827? An unauthenticated command-execution vulnerability (CWE-1188) in KGUARD DVR devices running firmware dating from 2016, where a system command execution service is exposed on all network interfaces without authentication.
Is CVE-2026-87827 being actively exploited? Yes — NVD’s own record attributes exploitation to the Mirai_ptea (Rimasuta) and Mirai_aurora botnets, with the technique documented as incorporated into the RapperBot malware family, though VulnCheck is the only KEV catalog currently listing it.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
How do I know if my device is affected? NVD states firmware released after 2017 restricts the vulnerable service to the localhost interface. If your KGUARD DVR (across the D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, D97xx, D98xx, or D99xx lines) has not had its firmware updated since before 2017, treat it as exposed.
Weakness classification and the described mechanism sourced from the National Vulnerability Database record for CVE-2026-87827, corroborated by Netlab 360’s threat research on the Mirai_ptea botnet. Exploitation status and the September 9, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. No CVSS score or EPSS data was available in our ingestion as of this writing. Aggregated September 20, 2026. See more vulnerability intelligence.