CVE-2026-73669: Signify Philips Hue Bridge Pro
High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.
The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces without authentication. An unauthenticated attacker with network access to the MQTT service on a vulnerable system can read data and control connected lights. Fixed in 1.77.2071318010.
Affected products
- Signify Philips Hue Bridge Pro: before 1.77.2071318010 (fixed in 1.77.2071318010)
Published 2026-08-13. Last modified 2026-08-26.