Refresh: Synology's camera count triples, Milestone's free tier fully shuts off, two new CVEs
2026-08-01
This cycle we refreshed ZoneMinder, Synology Surveillance Station, Milestone XProtect, Reolink, and Hikvision. Here's what changed:
**ZoneMinder**: version 1.38.3 ("Seek and Destroy", released 27 May 2026) is now the current stable release, with security fixes, crash/memory-safety fixes, and general bug fixes. No change to its criteria — still no built-in facial recognition or at-rest encryption.
**Synology Surveillance Station**: camera support has grown substantially — Synology now lists 20,000+ compatible IP cameras from 200+ brands under DSM 7.4 (up from the 8,300+ models we recorded in July), and DSM 7.4 is now the current platform version. The default 2 free device licences per NAS are confirmed unchanged; AES-256 encryption at rest and DVA-gated facial recognition remain as previously documented.
**Milestone XProtect**: device support grew to 16,300+ verified devices under Device Pack 14.1 (2026 R1), up from 16,000+. More notably, the free XProtect Essential+ tier — already discontinued for new activations since 2025 R2 — hit its final cutoff: activation of previously-downloaded copies stopped entirely on 1 January 2026. There is no longer any way to run XProtect for free.
**Reolink**: core facts unchanged — RTSP/ONVIF on wired/PoE models still works without a Reolink account for local use. We did find a new documented vulnerability: CVE-2026-57473 (CVSS 5.8), a weak-credential flaw in the Reolink Home Hub used by battery/WiFi cameras, letting an adjacent-network attacker brute-force camera credentials on firmware before v3.3.0.456_26031911.
**Hikvision**: alongside the well-known CVE-2021-36260 (CVSS 9.8 unauthenticated RCE), CISA added a second, older Hikvision flaw — CVE-2017-7921 (authentication bypass) — to its Known Exploited Vulnerabilities catalog on 2026-03-05, after confirming it is being actively exploited in the wild nine years after disclosure. A reminder that unpatched Hikvision deployments stay a live target long after the original advisory.
All refreshed sources are dated 2026-08-01. We re-checked Noviscan's claims against these updates — the at-rest-encryption comparison (Synology, Nx Witness, and Milestone all still gate it behind an opt-in setting or a pricier edition) still holds, so no change was needed there this cycle.