CVE-2026-3560Disclosure(philips / hue_bridge_v2)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch philips hue_bridge_v2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability. The specific flaw exists within the hk_hap_pair_storage_put function of the HomeKit implementation, which listens on TCP port 8080 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-28469.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hue_bridge_v2
  • hue_bridge_v2_firmware

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-16)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
hue_bridge_v2hue_bridge_v2_firmware

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-06: 1Mentions · 2026-03-13: 1Mentions · 2026-03-16: 2PoC Mentioned / Linked · 2026-03-06: 1Patch / Workaround · 2026-03-16: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 203-0603-1303-16
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-061
Disclosure1
2026-03-131
Disclosure1
2026-03-162
Disclosure1Patch1
Full discourse4 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-158|CVE-2026-3560] (Pwn2Own) Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVSS 8.8; Credit: Xilokar (@xilokar@mamot.fr)) https://www.zerodayinitiative.com/advisories/ZDI-26-158/

    Post summary

    A ZeroDay Initiative advisory announces a heap-based buffer overflow in Philips Hue Bridge HomeKit, providing vulnerability details but no exploit code, patch information, or evidence of active exploitation.

    00060611
    5.4K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3560 - High Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary cod... https://www.thehackerwire.com/vulnerability/CVE-2026-3560/ https://t.co/HGsc7daatV

    Post summary

    The post announces a high‑severity heap‑based buffer overflow vulnerability (CVE‑2026‑3560) in Philips Hue Bridge HomeKit, enabling remote code execution for network‑adjacent attackers.

    0000056
    136 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-3560: HIGH] Critical vulnerability in Philips Hue Bridge HomeKit allows remote attackers to execute arbitrary code. Exploit does not require authentication. Update your devices now!#cve,CVE-2026-3560,#cybersecurity https://cvefind.com/CVE-2026-3560

    Post summary

    A critical CVE-2026-3560 affecting Philips Hue Bridge HomeKit is announced, highlighting an RCE flaw and urging immediate firmware updates to mitigate the risk.

    0000035
    601 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3560 Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers … https://www.cve.org/CVERecord?id=CVE-2026-3560

    Post summary

    The text announces CVE‑2026‑3560, a heap‑based buffer overflow in Philips Hue Bridge HomeKit that enables remote code execution for network‑adjacent attackers; no PoC, exploit, patch, or active exploitation details are provided.

    00000141
    56.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWphilipshue_bridge_v2---
OSphilipshue_bridge_v2_firmware---

Explore more