lwIP TCP/IP Stack MQTT Client Application
A critical vulnerability (CVE-2026-87121) exists in the lwIP TCP/IP Stack MQTT Client Application, potentially allowing an attacker to execute code on affected devices. This vulnerability, an out-of-bounds write, affects versions 2.0.1 through 2.2.1. Organizations utilizing this software, particularly in critical infrastructure sectors like chemical, communications, manufacturing, energy, and transportation, are urged to update immediately.
The lwIP TCP/IP Stack MQTT Client Application is vulnerable to a critical security flaw (CVE-2026-87121), specifically an out-of-bounds write. This allows an attacker to gain full code execution on devices running affected versions – 2.0.1 through 2.2.1. The vulnerability has been reported by Shahriyar Jalayeri of ByteRay Ltd. and is impacting devices deployed worldwide, with company headquarters in Sweden. Affected organizations include those in critical infrastructure sectors such as chemical, communications, critical manufacturing, energy, financial services, healthcare and public health, and transportation systems, as well as water and wastewater systems. To mitigate this risk, users are strongly advised to update their lwIP TCP/IP Stack MQTT Client Application to the latest version. Additionally, CISA recommends implementing defensive measures such as minimizing network exposure for control system devices, isolating control systems networks from business networks, and utilizing secure remote access methods like VPNs, recognizing that VPNs themselves can have vulnerabilities. CISA encourages organizations to perform impact analysis and risk assessments and to proactively implement cybersecurity strategies for industrial control systems assets. Organizations should also follow established internal procedures and report any suspected malicious activity to CISA.