{"schema_version":1,"title":"Honeywell vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 8 vulnerabilities in Honeywell: 2 in the last 7 days and 4 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-13249, was published on 24 September 2026.","url":"https://junglewise.ai/threats/vendors/honeywell","json_url":"https://junglewise.ai/threats/vendors/honeywell.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/honeywell","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":2,"all_time":8,"critical":3,"exploited":0,"last_7_days":2,"last_30_days":2,"last_90_days":4,"last_365_days":8},"latest":[{"cve":"CVE-2026-13249","cvss":9.8,"epss":0.0057,"slug":"cve-2026-13249-an-unauthenticated-remote-code-execution-via-arbitrary-file","title":"Honeywell PD45 Industrial Printer unauthenticated arbitrary file upload","severity":"critical","exploited":false,"published_at":"2026-09-24T19:17:13.08+00:00","url":"https://junglewise.ai/threats/cve-2026-13249-an-unauthenticated-remote-code-execution-via-arbitrary-file"},{"cve":"CVE-2026-13248","cvss":8.8,"epss":0.0044,"slug":"cve-2026-13248-an-authenticated-remote-code-execution-via-arbitrary-file-write","title":"Honeywell PD45 Industrial Printer authenticated remote code execution via arbitrary file write","severity":"high","exploited":false,"published_at":"2026-09-24T19:17:12.917+00:00","url":"https://junglewise.ai/threats/cve-2026-13248-an-authenticated-remote-code-execution-via-arbitrary-file-write"},{"cve":"CVE-2026-17612","cvss":6.9,"slug":"cve-2026-17612-honeywell-s35-series-cameras-audit-log-disclosure","title":"Honeywell S35 Series Cameras audit log disclosure","severity":"info","exploited":false,"published_at":"2026-07-27T19:17:15.77+00:00","url":"https://junglewise.ai/threats/cve-2026-17612-honeywell-s35-series-cameras-audit-log-disclosure"},{"cve":"CVE-2026-13742","cvss":5.9,"slug":"cve-2026-13742-honeywell-iq-multiaccess-improper-signature-verification-via","title":"Honeywell IQ MultiAccess improper signature verification via TOCTOU","severity":"info","exploited":false,"published_at":"2026-06-29T16:16:39.11+00:00","url":"https://junglewise.ai/threats/cve-2026-13742-honeywell-iq-multiaccess-improper-signature-verification-via"},{"cve":"CVE-2026-5434","cvss":5.9,"slug":"cve-2026-5434-honeywell-control-network-module-sensitive-information-disclosure","title":"Honeywell Control Network Module sensitive information disclosure","severity":"medium","exploited":false,"published_at":"2026-05-21T09:16:30.41+00:00","url":"https://junglewise.ai/threats/cve-2026-5434-honeywell-control-network-module-sensitive-information-disclosure"},{"cve":"CVE-2026-5433","cvss":9.1,"slug":"cve-2026-5433-honeywell-control-network-module-command-injection-in-web","title":"Honeywell Control Network Module command injection in web interface","severity":"critical","exploited":false,"published_at":"2026-05-21T09:16:30.27+00:00","url":"https://junglewise.ai/threats/cve-2026-5433-honeywell-control-network-module-command-injection-in-web"},{"cve":"CVE-2026-4272","cvss":8.1,"epss":0.0045,"slug":"cve-2026-4272-honeywell-handheld-scanners-missing-authentication-in-base-station","title":"Honeywell Handheld Scanners missing authentication in base station","severity":"high","exploited":false,"published_at":"2026-04-05T22:16:01.697+00:00","url":"https://junglewise.ai/threats/cve-2026-4272-honeywell-handheld-scanners-missing-authentication-in-base-station"},{"cve":"CVE-2026-3611","cvss":10,"epss":0.0024,"slug":"cve-2026-3611-honeywell-iq4-series-bms-controller-missing-authentication-in-web","title":"Honeywell IQ4 Series BMS Controller missing authentication in web HMI","severity":"critical","exploited":false,"published_at":"2026-03-12T21:16:27.693+00:00","url":"https://junglewise.ai/threats/cve-2026-3611-honeywell-iq4-series-bms-controller-missing-authentication-in-web"}],"vendor":{"hub":true,"name":"Honeywell","slug":"honeywell","homepage":"https://www.honeywell.com/","description":"Honeywell is a multinational conglomerate that produces commercial and consumer products, engineering services, and aerospace systems.","url":"https://junglewise.ai/threats/vendors/honeywell"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":2}],"most_severe":[{"cve":"CVE-2026-3611","cvss":10,"epss":0.0024,"slug":"cve-2026-3611-honeywell-iq4-series-bms-controller-missing-authentication-in-web","title":"Honeywell IQ4 Series BMS Controller missing authentication in web HMI","severity":"critical","exploited":false,"published_at":"2026-03-12T21:16:27.693+00:00","url":"https://junglewise.ai/threats/cve-2026-3611-honeywell-iq4-series-bms-controller-missing-authentication-in-web"},{"cve":"CVE-2026-13249","cvss":9.8,"epss":0.0057,"slug":"cve-2026-13249-an-unauthenticated-remote-code-execution-via-arbitrary-file","title":"Honeywell PD45 Industrial Printer unauthenticated arbitrary file upload","severity":"critical","exploited":false,"published_at":"2026-09-24T19:17:13.08+00:00","url":"https://junglewise.ai/threats/cve-2026-13249-an-unauthenticated-remote-code-execution-via-arbitrary-file"},{"cve":"CVE-2026-5433","cvss":9.1,"slug":"cve-2026-5433-honeywell-control-network-module-command-injection-in-web","title":"Honeywell Control Network Module command injection in web interface","severity":"critical","exploited":false,"published_at":"2026-05-21T09:16:30.27+00:00","url":"https://junglewise.ai/threats/cve-2026-5433-honeywell-control-network-module-command-injection-in-web"},{"cve":"CVE-2026-13248","cvss":8.8,"epss":0.0044,"slug":"cve-2026-13248-an-authenticated-remote-code-execution-via-arbitrary-file-write","title":"Honeywell PD45 Industrial Printer authenticated remote code execution via arbitrary file write","severity":"high","exploited":false,"published_at":"2026-09-24T19:17:12.917+00:00","url":"https://junglewise.ai/threats/cve-2026-13248-an-authenticated-remote-code-execution-via-arbitrary-file-write"},{"cve":"CVE-2026-4272","cvss":8.1,"epss":0.0045,"slug":"cve-2026-4272-honeywell-handheld-scanners-missing-authentication-in-base-station","title":"Honeywell Handheld Scanners missing authentication in base station","severity":"high","exploited":false,"published_at":"2026-04-05T22:16:01.697+00:00","url":"https://junglewise.ai/threats/cve-2026-4272-honeywell-handheld-scanners-missing-authentication-in-base-station"},{"cve":"CVE-2026-5434","cvss":5.9,"slug":"cve-2026-5434-honeywell-control-network-module-sensitive-information-disclosure","title":"Honeywell Control Network Module sensitive information disclosure","severity":"medium","exploited":false,"published_at":"2026-05-21T09:16:30.41+00:00","url":"https://junglewise.ai/threats/cve-2026-5434-honeywell-control-network-module-sensitive-information-disclosure"},{"cve":"CVE-2026-17612","cvss":6.9,"slug":"cve-2026-17612-honeywell-s35-series-cameras-audit-log-disclosure","title":"Honeywell S35 Series Cameras audit log disclosure","severity":"info","exploited":false,"published_at":"2026-07-27T19:17:15.77+00:00","url":"https://junglewise.ai/threats/cve-2026-17612-honeywell-s35-series-cameras-audit-log-disclosure"},{"cve":"CVE-2026-13742","cvss":5.9,"slug":"cve-2026-13742-honeywell-iq-multiaccess-improper-signature-verification-via","title":"Honeywell IQ MultiAccess improper signature verification via TOCTOU","severity":"info","exploited":false,"published_at":"2026-06-29T16:16:39.11+00:00","url":"https://junglewise.ai/threats/cve-2026-13742-honeywell-iq-multiaccess-improper-signature-verification-via"}],"generated_at":"2026-09-26T11:07:00.153785+00:00","technologies":[]}