Philips maintains a moderately broad portfolio spanning healthcare information systems, clinical platforms, and consumer smart-home devices, creating a diverse attack surface that ranges from hospital networks to consumer endpoints. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, though the exposure does not show a meaningful pattern toward public exploit availability or confirmed in-the-wild exploitation. The recurring weaknesses cluster around hard-coded credentials, heap-based buffer overflows, and improper input validation, reflecting both the embedded-firmware demands of networked medical and consumer devices and the authentication and parsing challenges common to interconnected healthcare platforms. Defenders should prioritize Philips healthcare products deployed in clinical environments and inventory consumer smart-home infrastructure for credential exposure and memory-safety risks. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Philips over time
Of all the CVEs published by Philips as a CNA, 50.0% affect products that Philips develops as a vendor.
Of all the CVEs published that affect products developed by Philips, 2.6% are self-published by Philips as a CNA.
Signals from CVEs in this vendor scope (115 CVEs).
115 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-0199HIGH Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows | Apr 12, 2017 | 7.8 | 98 | YES | YES |
CVE-2017-0143HIGH The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gol | Mar 17, 2017 | 8.8 | 98 | YES | YES |
CVE-2018-5472CRITICAL Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to gain unauthorized access and in some cas | Mar 26, 2018 | 9.8 | 33 | NO | NO |
CVE-2018-5451CRITICAL In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct. Th | Mar 28, 2018 | 9.8 | 32 | NO | NO |
CVE-2021-27497CRITICAL Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. | Apr 1, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-8856CRITICAL Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, which it uses for encryption of internal data. | Sep 26, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-5474CRITICAL Philips Intellispace Portal all versions 7.0.x and 8.0.x have an input validation vulnerability that could allow a remote attacker to execute arbitrary code or cause the applicatio | Mar 26, 2018 | 9.8 | 31 | NO | NO |
CVE-2026-3560HIGH Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute a | Mar 13, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-3556HIGH Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code | Mar 13, 2026 | 8.8 | 30 | NO | NO |
CVE-2021-27501CRITICAL Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated | Apr 1, 2022 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (115 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Philips.
Media articles that mention a CVE ID that affects a product developed by Philips — matched by CVE ID, not by vendor name.