Auth bypass in Honeywell CCTV risks unauthorized feeds and account takeover

TL;DR
CISA warns of a critical vulnerability (CVE-2026-1670) in multiple Honeywell CCTV models that allows an unauthenticated attacker to change the recovery email on a device account, enabling account takeover and unauthorized access to camera feeds; as of Feb 17 there were no known public exploits; mitigations include limiting network exposure, isolating devices behind firewalls, and using secure VPN remote access; Honeywell has not issued a public advisory and users should contact support for patch guidance.
Critical infra Honeywell CCTVs vulnerable to auth bypass flaw BleepingComputer
Want the full story? Read the original reporting
Read on BleepingComputer