CVE-2026-3555Disclosure(philips / hue_bridge_v2)

MEDIUMCVSS 8.0 · HIGH

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for philips hue_bridge_v2 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. User interaction is required to exploit this vulnerability in that the user must initiate the device pairing process. The specific flaw exists within the handling of custom Zigbee ZCL frames in the Model Info download functionality. The issue results from the lack of proper validation of the size of data prior to copying it to a fixed-size heap buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-28276.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hue_bridge_v2
  • hue_bridge_v2_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-05-21)
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
hue_bridge_v2hue_bridge_v2_firmware

1 version affected across 2 products

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-06: 1Mentions · 2026-03-13: 1Mentions · 2026-03-16: 1Mentions · 2026-05-21: 3PoC Mentioned / Linked · 2026-03-06: 1PoC Mentioned / Linked · 2026-05-21: 1Active Exploitation · 2026-05-21: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 1Technical Details · 2026-05-21: 103-0603-1303-1605-21
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Exploit
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-061
Disclosure1
2026-03-131
Disclosure1
2026-03-161
Disclosure1
2026-05-213
Exploit1General2
Full discourse6 posts
  • 0xor0ne@0xor0ne
    Exploit

    RCE on the Philips Hue Bridge via a heap overflow in ZCL frame processing, exploited over Zigbee (CVE-2026-3555) (Pwn2Own) https://www.synacktiv.com/en/publications/make-it-blink-over-the-air-exploitation-of-the-philips-hue-bridge Credits Mehdi Talbi, Matthieu Breuil (@Synacktiv) #infosec https://t.co/fnY8l3QNTU

    Post summary

    The tweet reports a successful remote code execution achieved via a heap overflow in Philips Hue Bridge’s Zigbee stack, provides a link to a detailed exploit publication, and confirms the vulnerability’s exploitation in a Pwn2Own event.

    1220117438.3K
    92.2K followersView on X
  • Council 𝘰𝘯 Foreign Elations@ForeignElations
    General

    Terribly sorry! I am in Canada and this is aboot the @Philips Hue Bridge exploit via CVE-2026-3555. Will I need to buy new things for my house? Do I need to unplug all my Hue lights and plugs to be safe? This is my first drive-by attack.

    Post summary

    The user expresses concern about CVE-2026-3555 but offers no evidence of exploitation, PoC, or mitigation.

    20000495
    190 followersView on X
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-153|CVE-2026-3555] (Pwn2Own) Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVSS 8.0; Credit: Mehdi Talbi, Matthieu Breuil, Théo Gordyjan from @Synacktiv) https://www.zerodayinitiative.com/advisories/ZDI-26-153/

    Post summary

    The advisory announces CVE‑2026‑3555, a heap‑based buffer overflow in the Philips Hue Bridge Zigbee stack that enables remote code execution, is rated CVSS 8.0, and references a PoC via the provided ZDI link.

    00020575
    5.4K followersView on X
  • Council 𝘰𝘯 Foreign Elations@ForeignElations
    General

    Zigbee (CVE-2026-3555) is why we physically moat.

    Post summary

    The text references CVE-2026-3555 but provides no concrete or actionable information about it.

    0000047
    190 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3555 - High Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary... https://www.thehackerwire.com/vulnerability/CVE-2026-3555/ https://t.co/E9OndpY2rC

    Post summary

    This announcement describes a high‑severity heap-based buffer overflow in the Philips Hue Bridge Zigbee stack that allows remote code execution for network‑adjacent attackers; no PoC, active exploitation, or patch information is included.

    0000058
    136 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3555 Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attack… https://www.cve.org/CVERecord?id=CVE-2026-3555

    Post summary

    The post announces the CVE‑2026‑3555 vulnerability—a heap‑based buffer overflow that allows remote code execution on Philips Hue Bridges—without providing PoC, exploit, patch, or evidence of active exploitation.

    00000165
    56.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWphilipshue_bridge_v2---
OSphilipshue_bridge_v2_firmware---

Explore more