lwIP TCP/IP Stack MQTT Client Application
CISA warns lwIP MQTT client versions 2.0.1 through 2.2.1 have critical CVE-2026-87121.
CISA published ICSA-26-265-01 for an out-of-bounds write in the lwIP MQTT client, CVE-2026-87121, affecting versions 2.0.1 through 2.2.1. CVSS v3.1 is 9.8 and CVSS v4.0 is 9.3; successful exploitation could allow full code execution. The stack is deployed across multiple critical infrastructure sectors worldwide. CISA says no known public exploitation has been reported.
68