Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/philips/Hue-Bridge

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-3562 is a medium severity vulnerability in the Philips Hue Bridge version 1.73.1973146020. It involves improper verification of a cryptographic signature in the ed25519_sign_open function, allowing network-adjacent attackers to bypass authentication and execute arbitrary code without user interaction. The flaw is due to CWE-347: Improper Verification of Cryptographic Signature. No patch or official fix information is currently available.

Join the discussion

CVE-2026-3561 is a heap-based buffer overflow vulnerability in the Philips Hue Bridge affecting version 1.73.1973146020. It occurs in the handling of PUT requests to the hk_hap characteristics endpoint, where insufficient validation of user-supplied data length allows overwriting a heap buffer. Although exploitation requires authentication, the authentication mechanism can be bypassed, enabling network-adjacent attackers to execute arbitrary code on the device. The vulnerability has a high severity with a CVSS score of 8. No patch or official remediation is currently documented.

Join the discussion

CVE-2026-3560 is a heap-based buffer overflow vulnerability in the Philips Hue Bridge's HomeKit implementation, specifically in the hk_hap_pair_storage_put function. This flaw allows network-adjacent attackers to execute arbitrary code without authentication by sending specially crafted data to TCP port 8080. The vulnerability arises from improper validation of user-supplied data length before copying it to a heap buffer. It affects version 1.73.1973146020 of the Philips Hue Bridge. The CVSS score is 8.8, indicating high severity. No patch or official remediation guidance is currently provided by the vendor. There are no known exploits in the wild at this time.

Join the discussion

CVE-2026-3558 is a high-severity vulnerability in the Philips Hue Bridge version 1.73.1973146020 that allows network-adjacent attackers to bypass authentication. The flaw exists in the HomeKit Accessory Protocol service, which listens on TCP port 8080 and does not require authentication before granting access to critical functions. This missing authentication can be exploited without user interaction and can lead to unauthorized control of the device. No patch or official fix information is currently provided. There are no known exploits in the wild at this time.

Join the discussion

CVE-2026-3557 is a heap-based buffer overflow vulnerability in the Philips Hue Bridge, specifically in the hap_pair_verify_handler function of the hk_hap service listening on TCP port 8080. This flaw allows a network-adjacent attacker to execute arbitrary code with root privileges by exploiting improper validation of user-supplied data length. Although authentication is required, the authentication mechanism can be bypassed. The vulnerability has a high severity with a CVSS score of 8. No patch or official remediation information is currently provided.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/philips/Hue-Bridge
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses