SecAlerts
philips logo

philips

Security Risk Profile

62
/100
high

Security Risk Score

Comprehensive risk assessment based on 140 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from October 5, 2013 to present

140
Total CVEs
88
Critical+High
3
Exploited
73
Unpatched

Threat Assessment

Avg CVSS
7.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
73
Critical/High
Risk Level
62/100
high
⚠️ 3 Active Exploits 1 Zero-Days

Severity Distribution

Critical
13
High
75
Medium
47
Low
4

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
11

Age Distribution

Common Weaknesses (CWE)

1
Buffer Overflow
8
2
Infoleak
7
3
Input Validation
7
4
XSS
4
5
Weak Encryption
4

Most Affected Products

1. Philips Hue Bridge49
2. Philips Patient Information Center iX30
3. Philips IntelliSpace Portal24
4. Philips Vue PACS12
5. Philips Hue Bridge V2 Firmware10

Recent Vulnerabilities

See more →
CVE-2026-3562
CVSS 8.8EPSS 0%high

(Pwn2Own) Philips Hue Bridge hk_hap Ed25519 Signature Verification Authentication Bypass Vulnerability

3/13/2026🔧 No Patch
CVE-2026-3561
CVSS 8.0EPSS 0%high

(Pwn2Own) Philips Hue Bridge hk_hap characteristics Heap-based Buffer Overflow Remote Code Execution Vulnerability

3/13/2026🔧 No Patch
CVE-2026-3560
CVSS 8.8EPSS 0%high

(Pwn2Own) Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability

3/13/2026🔧 No Patch
CVE-2026-3559
CVSS 8.1EPSS 0%high

(Pwn2Own) Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability

3/13/2026🔧 No Patch
CVE-2026-3558
CVSS 8.1EPSS 0%high

(Pwn2Own) Philips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass Vulnerability

3/13/2026🔧 No Patch
CVE-2026-3557
CVSS 8.0EPSS 0%high

(Pwn2Own) Philips Hue Bridge hap_pair_verify_handler Sub-TLV Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

3/13/2026🔧 No Patch
CVE-2026-3556
CVSS 8.8EPSS 0%high

(Pwn2Own) Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability

3/13/2026🔧 No Patch
CVE-2026-3555
CVSS 8.0EPSS 0%high

(Pwn2Own) Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability

3/13/2026🔧 No Patch
ZDI-26-157
CVSS 8.1high

(Pwn2Own) Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability

3/6/2026🔧 No Patch
ZDI-CAN-28451
CVSS 8.1high

ZDI-26-157: (Pwn2Own) Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability

3/6/2026🔧 No Patch

Monitor philips in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.