CVE•Published 2026-05-21•Modified 2026-07-28•0 articles on news•6 live references•NVD data
CVE-2026-5434
Vulnerability data via NVD (ingested)
CVSS v3.1
5.9
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS percentile
—
Weaknesses (CWE)
Description
Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially resulting in unintended access to protected data. Honeywell recommends updating to the most recent version of this product, service or offering [200.1]. The CNM versions affected are from [100.1, 101.1, 110.1, and 110.2].
Timeline
Published 2026-05-21
Modified 2026-07-28
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
More intel sources (5)
Shodan report
vuln:CVE-2026-5434Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-5434Censys host search filtered to this CVE id.
grep.app
CVE-2026-5434Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-5434GitHub code search for direct mentions.
Google dork
"CVE-2026-5434" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (7)
CVE-2026-54347 repos
eltociear/awesome-molt-ecosystemDockerfile
The brutally honest map of where AI-agent money actually flows. 51 rounds, 137 angles, 230+ platforms. 3 self-hosted x402 v2 endpoints + 3 tools in the official MCP Registry. 385K …
KhaledSaeed18/node-express-boilerplateTypeScript
Production-ready Express + TypeScript backend boilerplate with clean layered architecture, dependency injection, JWT + CSRF security, structured logging, automated CI/CD, Docker su…
dinosn/cve-2026-2005Python
CVE-2026-2005 — PostgreSQL pgcrypto heap overflow RCE exploit
nvdigitalsolutions/mcp-ai-wpoosPHP
NV Digital Open Operator System (NVoOS) is an Object-Oriented AI framework for WordPress connecting your data with OpenAI, Gemini, Anthropic, DeepSeek, Hugging Face, Cloudflare, Op…
yash2121ja/vuln-intel-dbPython
Open-source vulnerability intelligence database — 243K+ advisories from Debian, Alpine, GHSA, CISA KEV, EPSS. Updated every 6 hours.
raspberryhusky/fscan-rsRust
内网综合安全扫描工具 — Go fscan v2.1.3 完全重写为 Rust,纯 AI 生成
faby1507/Tesi-triennale-Sviluppo-e-caratterizzazione-di-un-NIDS-basato-su-modelli-di-deep-learningPython
Modello multimodale traffico testo robusto a variazioni e perturbazioni
We haven't classified any articles referencing CVE-2026-5434 yet. The external references above still apply.