HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Authentication Bypass in Honeywell IQ4x BMS Controllers (CVE‑2026‑3611) Threatens Facility Operations

A missing‑authentication flaw (CVE‑2026‑3611) in Honeywell IQ4x building‑management controllers allows unauthenticated attackers to alter HVAC, lighting, fire‑safety and other critical functions. The vulnerability scores 10.0 CVSS and affects firmware versions prior to 4.36, exposing commercial, healthcare, manufacturing, and government facilities to operational disruption.

LiveThreat™ Intelligence · 📅 March 10, 2026· 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
5 recommended
📰
Source
cisa.gov

Critical Authentication Bypass in Honeywell IQ4x BMS Controllers (CVE‑2026‑3611) Threatens Facility Operations

What It Is – A missing‑authentication flaw in the web‑based HMI of Honeywell’s IQ4x building‑management system (BMS) controllers allows an unauthenticated attacker to read or modify controller settings, command HVAC, lighting, fire‑safety subsystems, or trigger a denial‑of‑service.

Exploitability – The vulnerability is publicly disclosed (CVE‑2026‑3611) with a CVSS 3.1 base score of 10.0 (Critical). No public exploit code has been released, but the attack requires only network access to the controller’s default web interface, making exploitation trivial in environments where default configurations remain unchanged.

Affected Products – Honeywell IQ4x series controllers (IQ4E, IQ412, IQ422, IQ4NC, IQ41x, IQ3, IQECO) running firmware ≥ v3.50 & < 4.36 (build 4.3.7.9).

TPRM Impact

  • Facilities that rely on these controllers (commercial real‑estate, hospitals, manufacturing plants, government sites) inherit a direct supply‑chain risk.
  • A compromised BMS can disrupt critical environmental controls, fire‑suppression systems, and occupant safety, leading to operational downtime and potential regulatory violations.

Recommended Actions

  • Inventory all Honeywell IQ4x controllers and verify firmware versions.
  • Upgrade to Honeywell‑provided firmware ≥ 4.36 (or later) that enforces authentication.
  • Disable the factory‑default web HMI or restrict it to a segmented management VLAN.
  • Implement network‑level access controls (firewall, ACLs) to limit inbound traffic to trusted management hosts.
  • Conduct a penetration test of the BMS network segment to confirm remediation.

Source: CISA Advisory – ICSA‑26‑069‑03

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-03

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →