CVE-2026-3556Disclosure(philips / hue_bridge_v2)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability. The specific flaw exists within the hk_hap_pair_storage_put function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the HomeKit service. Was ZDI-CAN-28326.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hue_bridge_v2
  • hue_bridge_v2_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-16)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
hue_bridge_v2hue_bridge_v2_firmware

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-06: 1Mentions · 2026-03-13: 1Mentions · 2026-03-16: 2PoC Mentioned / Linked · 2026-03-06: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 203-0603-1303-16
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-061
Disclosure1
2026-03-131
Disclosure1
2026-03-162
Disclosure2
Full discourse4 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-154|CVE-2026-3556] (Pwn2Own) Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVSS 8.8; Credit: InnoEdge Labs) https://www.zerodayinitiative.com/advisories/ZDI-26-154/

    Post summary

    A heap-based buffer overflow vulnerability (CVE‑2026‑3556) in Philips Hue Bridge HomeKit Pair‑Setup was disclosed by InnoEdge Labs, with CVSS 8.8 and a link to a Zero Day Initiative advisory containing further details.

    00020405
    5.4K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3556 - High Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected... https://www.thehackerwire.com/vulnerability/CVE-2026-3556/ https://t.co/AB7Sk71yb2

    Post summary

    The post announces a heap‑based buffer overflow in Philips Hue Bridge allowing remote code execution, without evidence of PoC, patch, or active exploitation.

    0001060
    136 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3556: HIGH] Critical security issue in Philips Hue Bridge! A buffer overflow vulnerability allows attackers to execute code without authentication. Stay safe, update your devices.#cve,CVE-2026-3556,#cybersecurity https://cvefind.com/CVE-2026-3556

    Post summary

    The tweet announces a critical buffer overflow vulnerability (CVE-2026-3556) in Philips Hue Bridge that could allow code execution without authentication, urging users to update.

    0000030
    601 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3556 Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute ar… https://www.cve.org/CVERecord?id=CVE-2026-3556

    Post summary

    The statement announces CVE‑2026‑3556 as a heap‑based buffer overflow Remote Code Execution vulnerability in Philips Hue Bridge HomeKit Pair‑Setup, noting that network‑adjacent attackers can exploit it, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    00000155
    56.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWphilipshue_bridge_v2---
OSphilipshue_bridge_v2_firmware---

Explore more