CVE-2026-1670Disclosure

MEDIUMCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 15 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 38 mentions across 9 observed days
  • Momentum state: declining

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 13 signals
  • Technical details provided in 30 signals
  • Disclosure: 23 classified signals
  • General: 4 classified signals
  • Peaked 6d ago at 15 mentions (2026-02-19); latest day: 1
  • 38 total mentions across 9 days

Deep dive

Activity timeline38 mentions / 9d
0481115Mentions · 2026-02-17: 4Mentions · 2026-02-18: 6Mentions · 2026-02-19: 15Mentions · 2026-02-20: 8Mentions · 2026-02-22: 1Mentions · 2026-02-24: 1Mentions · 2026-02-26: 1Mentions · 2026-03-03: 1Mentions · 2026-04-05: 1Active Exploitation · 2026-02-19: 1Active Exploitation · 2026-03-03: 1Active Exploitation · 2026-04-05: 1Patch / Workaround · 2026-02-18: 2Patch / Workaround · 2026-02-19: 4Patch / Workaround · 2026-02-20: 3Patch / Workaround · 2026-02-22: 1Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-04-05: 1Technical Details · 2026-02-17: 4Technical Details · 2026-02-18: 5Technical Details · 2026-02-19: 12Technical Details · 2026-02-20: 6Technical Details · 2026-02-22: 1Technical Details · 2026-02-26: 1Technical Details · 2026-04-05: 102-1702-1802-1902-2002-2202-2402-2603-0304-05
Signal classification4 categories
Disclosure
2360.5%
Patch
923.7%
General
410.5%
Active Exploitation
25.3%
Referenced assets47 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-174
Disclosure4
2026-02-186
Disclosure4Patch2
2026-02-1915
Active Exploitation1Disclosure10General2Patch2
2026-02-208
Disclosure3General2Patch3
2026-02-221
Disclosure1
2026-02-241
Disclosure1
2026-02-261
Patch1
2026-03-031
Active Exploitation1
2026-04-051
Patch1
Full discourse20 posts
  • Gray Hats@the_yellow_fall
    Patch

    CISA warns of Honeywell CCTV flaw CVE-2026-1670. Unauthenticated attackers can reset passwords & hijack feeds. Update firmware immediately. #Honeywell #CCTV #CyberSecurity #IoT #CVE20261670 #InfoSec #PhysicalSecurity https://securityonline.info/critical-honeywell-cctv-flaw-cvss-9-8-allows-unauthenticated-takeover/

    Post summary

    CISA alerts that Honeywell CCTV’s CVE-2026-1670 allows unauthenticated password resets and feed hijacking; immediate firmware updates are recommended to mitigate the CVSS 9.8 vulnerability.

    16162532
    10.3K followersView on X
  • IntelOpsAnalyst@Threat2Trust
    Patch

    Counterintelligence isn’t only spies. It’s also surveillance compromise. CISA published an advisory describing a critical auth-related weakness affecting specific Honeywell CCTV products (CVE-2026-1670), where exploitation could enable account takeover and unauthorized camera feed access. Counterintel lens: if cameras are compromised, your: site layouts guard patterns asset movements executive routines can become intelligence for adversaries. 3 actions I’d prioritize: Isolate CCTV/IoT networks (no internet exposure by default) Patch governance with vendors (who/when/how) Alert on admin changes (recovery email, password resets, new accounts) Specialists: Do you treat physical security systems like Tier-1 cyber assets yet? #CounterIntelligence #ConvergedSecurity #PhysicalSecurity #CCTV #ICS #VulnerabilityManagement #ThreatIntelligence #CyberPhysical

    Post summary

    CISA released an advisory on CVE‑2026‑1670, a critical authentication flaw in Honeywell CCTV that could allow account takeover and unauthorized feed access, and the post stresses patching and mitigation steps.

    10061240
    15 followersView on X
  • Information Security Buzz@Info_Sec_Buzz
    Disclosure

    The @CISAgov has issued an alert over CVE-2026-1670, a severe vulnerability affecting several Honeywell camera models. The flaw could allow attackers to take over accounts and access live camera feeds without authentication. 🔗 Read more: https://informationsecuritybuzz.com/cisa-warns-of-critical-security-vulnerability-in-honeywell-cameras/ #ISBNews

    Post summary

    CISA has issued an alert about CVE‑2026‑1670, a severe vulnerability in Honeywell cameras that could allow attackers to take over accounts and access live feeds without authentication, but no PoC, exploit code, or patch information is shared.

    11030133
    20.6K followersView on X
  • Directoratul Național de Securitate Cibernetică@DNSC_RO
    Disclosure

    🚨 ALERTĂ - Vulnerabilitate critică la nivelul unor produse Honeywell 🔔 CVE-2026-1670 este o vulnerabilitate critică, scor CVSS v3.1 de 9.8, care afectează mai multe produse Honeywell CCTV. 👉 Citiți alerta: https://www.dnsc.ro/citeste/alerta-vulnerabilitate-critica-la-nivelul-unor-produse-honeywell #DNSC #SigurantaOnline #Alert #CyberSecurity https://t.co/2m0ymOHhh4

    Post summary

    The tweet announces CVE-2026-1670 as a critical vulnerability (CVSS 9.8) affecting Honeywell CCTV products, without providing PoC, exploit, or patch details.

    02020132
    4.6K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Disclosure

    A critical 9.8-severity flaw (CVE-2026-1670) in Honeywell CCTVs allows unauthenticated attackers to bypass auth and change recovery emails via an exposed API, risking full account takeover. #Honeywell #CISA #USA https://ift.tt/OLHJA4T

    Post summary

    A newly disclosed critical vulnerability (CVE‑2026‑1670) in Honeywell CCTV systems allows unauthenticated users to bypass authentication and alter recovery emails via an exposed API, presenting a full account takeover risk.

    01030139
    3.6K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #CISA warns of a critical authentication bypass vulnerability, #CVE-2026-1670, in #Honeywell CCTVs allowing unauthorized access or account hijacking. CISA advises to isolate camera systems from Internet, use firewalls, and place remote devices behind secure networks.

    Post summary

    A CISA advisory warns of a critical authentication bypass in Honeywell CCTV cameras (CVE‑2026‑1670) and recommends isolation, firewalling, and secure network placement as mitigations.

    01100217
    7.2K followersView on X
  • ܛܔܔܔܛܔܛܔܛ@skocherhan
    Disclosure

    "The U.S. Cybersecurity and Infrastructure Security Agency has issued a warning about a critical vulnerability affecting multiple Honeywell CCTV camera models used across commercial, industrial, and critical infrastructure environments worldwide. Tracked as CVE-2026-1670 and discovered by security researcher Souvik Kanda, this authentication bypass flaw carries a CVSS severity score of 9.8 out of 10. The vulnerability impacts several Honeywell camera models including the I-HIB2PI-UL 2MP IP (6.1.22.1216) SMB NDAA MVO-3, PTZ WDR 2MP 32M, 25M IPC (WDR_2MP_32M_PTZ_v2.0)"

    Post summary

    An advisory announces CVE‑2026‑1670, an authentication bypass vulnerability with CVSS 9.8, affecting multiple Honeywell CCTV camera models; no PoC, exploit, or patch details are provided.

    10010229
    26.2K followersView on X
  • キタきつね@foxbook
    Disclosure

    CISA、ハネウェルのCCTVにおける重大な認証バイパス脆弱性CVE-2026-1670について警告 CISA alerts to critical auth bypass CVE-2026-1670 in Honeywell CCTVs #SecurityAffairs (Feb 19) https://securityaffairs.com/188234/security/cisa-alerts-to-critical-auth-bypass-cve-2026-1670-in-honeywell-cctvs.html

    Post summary

    The message announces a CISA alert for a critical authentication bypass vulnerability (CVE‑2026‑1670) affecting Honeywell CCTV devices.

    00020194
    4.7K followersView on X
  • Alborz Safe@EthicalSafe
    Patch

    امروزه همه از دوربین های مدار بسته یا CCTV ها استفاده می کنند که خیلی وقت ها از طریق اینترنت ، قابل دسترسی هستند. برای دوربین های شرکت Honeywell آسیب پذیری با کد شناسایی CVE-2026-1670 منتشر شده این که باعث کنترل کامل هکر به این مدل دوربین ها می شود، Firmware دوربین را update کنید https://t.co/JHwogpQC7B

    Post summary

    CVE-2026-1670 affects Honeywell CCTV cameras, allowing attackers full control; users are urged to update camera firmware to mitigate the risk.

    0002062
    2 followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs
    Disclosure

    #CISA alerts to critical auth bypass CVE-2026-1670 in #Honeywell #CCTVs https://securityaffairs.com/188234/security/cisa-alerts-to-critical-auth-bypass-cve-2026-1670-in-honeywell-cctvs.html #securityaffairs #hacking

    Post summary

    CISA has issued an alert for a critical authentication bypass (CVE‑2026‑1670) affecting Honeywell CCTVs, highlighting the vulnerability's severity.

    01010165
    37.5K followersView on X
  • The DefendOps Diaries@DefendOpsHQ
    Disclosure

    A single overlooked API flaw lets hackers hijack Honeywell CCTV cameras without even logging in—just how easy is it to take over a surveillance system? The answer is unsettling https://thedefendopsdiaries.com/cve-2026-1670-how-a-simple-api-flaw-exposed-honeywell-cctv-systems-to-hijacking/

    Post summary

    The article announces CVE‑2026‑1670, a Honeywell CCTV API flaw that lets attackers hijack cameras without authentication, but provides no exploit, patch or technical depth.

    0001139
    32 followersView on X
  • Lewis Lu@theLewisLu
    Patch

    @the_yellow_fall CVE-2026-1670: unauth password reset → hijack CCTV feeds. Patch firmware ASAP + keep cameras off the public internet (VPN/segmented LAN).

    Post summary

    CVE-2026-1670 permits unauthenticated password resets that can hijack CCTV feeds; firmware patch and network isolation are urgently advised.

    0002070
    389 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1670: CRITICAL] The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.#cve,CVE-2026-1670,#cybersecurity https://cvefind.com/CVE-2026-1670

    Post summary

    The tweet announces CVE‑2026‑1670, describing a critical unauthenticated API flaw that lets attackers change recovery email addresses, but it provides no PoC, exploit code, or patch details.

    1001068
    580 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1670 The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email ad… https://www.cve.org/CVERecord?id=CVE-2026-1670

    Post summary

    CVE-2026-1670 involves an unauthenticated API endpoint that could let attackers alter password recovery emails; no PoC, exploit code, active exploitation, or patch information is provided.

    00020142
    56.4K followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs
    General

    #CISA alerts to critical auth bypass CVE-2026-1670 in #Honeywell #CCTVs https://securityaffairs.com/188234/security/cisa-alerts-to-critical-auth-bypass-cve-2026-1670-in-honeywell-cctvs.html #securityaffairs #hacking

    Post summary

    CISA has issued an alert for a critical authentication bypass (CVE-2026-1670) in Honeywell CCTVs, but the notice does not provide a PoC, exploit code, or patch details.

    00001194
    37.5K followersView on X
  • Shah Sheikh@shah_sheikh
    General

    [Information Security Buzz] CISA Warns of Critical Security Vulnerability in Honeywell Cameras. CISA has warned that a critical security vulnerability (CVE-2026-1670) has been identified in four Honeywell CCTV camera models.  “Successful exploitation... http://ow.ly/ZqvV106uP3C

    Post summary

    CISA warns of CVE-2026-1670 as a critical vulnerability in four Honeywell CCTV cameras, but the text offers no PoC, exploit details, or patch information.

    0001049
    2.2K followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    CVSS 9.8 vulnerability in Honeywell cctv products. Extensive info, incl. fix info, at SecAlerts: CVE-2026-1670, CVSS 9.8: https://secalerts.co/vulnerability/CVE-2026-1670 #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp #secalerts #CVE20261670 #honeywell https://t.co/fyqf2daWgx

    Post summary

    This tweet highlights the high‑severity CVE‑2026‑1670 that impacts Honeywell CCTV systems, providing a link to a SecAlerts page that includes technical details and fix information.

    00100327
    796 followersView on X
  • jens@wizzper_de
    Disclosure

    👉 Neue Sicherheitsgefahr für IP-Kameras! Eine kritische Schwachstelle (CVE-2026-1670) in Honeywell-CCTV kann Angreifern Zugriff ohne Passwort ermöglichen. ➡️ Jetzt verstehen, wie das technisch funktioniert & wie du deine Geräte wirklich sicherst: 🔗 https://wizzper.de/news/kritische-sicherheitsluecke-in-honeywell-ueberwachungskameras-was-jetzt-zu-tun-ist #CyberSecurity #IoT #Honeywell #CVE2026 #ITSec #WizzperNews

    Post summary

    The post discloses a critical unauthenticated access vulnerability (CVE‑2026‑1670) in Honeywell CCTV devices and links to a guide on how to secure them.

    0001057
    30 followersView on X
  • Commonwealth Sentinel@CwealthSentinel
    Disclosure

    CISA alerts to critical auth bypass CVE-2026-1670 in Honeywell CCTVs https://ift.tt/mH0PZSY

    Post summary

    CISA has issued an alert about a critical authentication bypass vulnerability (CVE‑2026‑1670) impacting Honeywell CCTV systems.

    0001068
    1.9K followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 CISA Flags Critical Honeywell CCTV Account-Takeover Flaw (CVE-2026-1670, CVSS 9.8) CVE-2026-1670 is a missing-authentication issue that lets an unauthenticated attacker change the device’s password-recovery email, then reset the password to hijack the admin account and access/alter CCTV feeds and settings. Immediate mitigation is to remove internet exposure, segment/ACL management interfaces, and apply Honeywell guidance/updates as available. 🎯 Target: Global/CCTV Surveillance #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/honeywell-cctv-products-vulnerability/

    Post summary

    The post announces CISA’s flag of CVE-2026-1670, a missing-authentication flaw in Honeywell CCTV that permits admin takeover, and offers immediate mitigation instructions and vendor guidance.

    0001055
    174 followersView on X

Explore more