← Vulnerability feed

Vulnerability record · CVE-2026-3559 · published 16 March 2026

CVE-2026-3559: Philips hue bridge v2 firmware vulnerability

Philips · Hue Bridge V2 Firmware

Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the SRP authentication mechanism in the HomeKit Accessory Protocol service, which listens on TCP port 8080 by default. The issue results from the use of a static nonce value. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-28451.

8.1 CVSS 3.0 High EPSS 0.39% · top 69.4% CWE-323 · CWE-323
8.1CVSS 3.0 base score
0.39%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the SRP authentication mechanism in the HomeKit Accessory Protocol service, which listens on TCP port 8080 by default. The issue results from the use of a static nonce value. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-28451.

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-3559 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-3560Philips hue bridge v2 firmware heap-based buffer overflow vulnerabilityPhilips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-…EPSS 0.54%8.8CVE-2026-3562Philips hue bridge v2 firmware improper verification of cryptographic signature vulnerabilityPhilips Hue Bridge hk_hap Ed25519 Signature Verification Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to…EPSS 0.31%8.8CVE-2026-3556Philips hue bridge v2 firmware heap-based buffer overflow vulnerabilityPhilips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent atta…EPSS 0.54%8.1CVE-2026-3558Philips hue bridge v2 firmware missing authentication for critical function vulnerabilityPhilips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass Vulnerability. This vulnerability allows network-adjacent …EPSS 0.40%8.0CVE-2026-3561Philips hue bridge v2 firmware heap-based buffer overflow vulnerabilityPhilips Hue Bridge hk_hap characteristics Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent …EPSS 0.58%8.0CVE-2026-3555Philips hue bridge v2 firmware heap-based buffer overflow vulnerabilityPhilips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows netw…EPSS 0.37%8.0CVE-2026-3557Philips hue bridge v2 firmware heap-based buffer overflow vulnerabilityPhilips Hue Bridge hap_pair_verify_handler Sub-TLV Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows …EPSS 0.58%7.9CVE-2020-6007Philips hue bridge v2 firmware heap-based buffer overflow vulnerabilityPhilips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during t…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2026-3559), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.