Ikea's vulnerability footprint centers on a narrow set of smart-home and IoT products, primarily its TRADFRI lighting gateway and LED appliances and their associated firmware. The recurring signal reflects application-layer input handling and request-routing weaknesses typical of networked consumer devices, alongside instances where data-type validation and unexpected protocol inputs have surfaced as durable concerns. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ikea over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39064HIGH An attacker sending a single malformed IEEE 802.15.4 (Zigbee) frame makes the TRÅDFRI bulb blink, and if they replay (i.e. resend) the same frame multiple times, the bulb performs | Oct 14, 2022 | 8.1 | 26 | NO | NO |
CVE-2022-39065MEDIUM A single malformed IEEE 802.15.4 (Zigbee) frame makes the TRÅDFRI gateway unresponsive, such that connected lighting cannot be controlled with the IKEA Home Smart app and TRÅDFRI r | Oct 14, 2022 | 6.5 | 23 | NO | NO |
CVE-2026-3588MEDIUM A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private keys by sending a crafted request. | Mar 9, 2026 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ikea.
Media articles that mention a CVE ID that affects a product developed by Ikea — matched by CVE ID, not by vendor name.