CVE-2026-1670: Honeywell 25m Ipc

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.

Affected products

Published 2026-02-17. Last modified 2026-06-17.