CVE-2026-73669: Signify Philips Hue Bridge Pro

High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.

The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces without authentication. An unauthenticated attacker with network access to the MQTT service on a vulnerable system can read data and control connected lights. Fixed in 1.77.2071318010.

Affected products

  • Signify Philips Hue Bridge Pro: before 1.77.2071318010 (fixed in 1.77.2071318010)

Published 2026-08-13. Last modified 2026-08-26.