CISA Details Two lwIP Flaws in Versions 2.0.1–2.2.1
CISA warned that lwIP 2.0.1–2.2.1 has an MQTT out-of-bounds write and an adjacent-network double-free, with no known exploitation.
On September 22, 2026, CISA published two ICS advisories on distinct flaws in lwIP versions 2.0.1 through 2.2.1. ICSA-26-265-01 covers CVE-2026-87121, an out-of-bounds write in the MQTT client scored CVSS v3.1 9.8 and CVSS v4.0 9.3; CISA says successful exploitation could allow unauthenticated full code execution, and notes the stack is used across multiple critical infrastructure sectors worldwide. ICSA-26-265-02 covers CVE-2026-91018, a double-free (CWE-415) in the lwIP API scored CVSS v3.1 8.8 High and CVSS v4.0 8.7 High. That flaw has an adjacent-network vector and is not remotely exploitable; impacts can include a crash, denial of service, memory corruption, or code execution. Eric Evenchick of Tetrel Security reported CVE-2026-91018. The advisories do not conflict; CISA says no known public exploitation has been reported for either issue.
- On 2026-09-22 CISA published ICSA-26-265-01 and ICSA-26-265-02 for lwIP versions 2.0.1 through 2.2.1.
- CVE-2026-87121 is an out-of-bounds write in the lwIP MQTT client, scored CVSS v3.1 9.8 and CVSS v4.0 9.3, and CISA says exploitation could allow unauthenticated full code execution.
- CVE-2026-91018 is a double-free (CWE-415) in the lwIP API, scored CVSS v3.1 8.8 High and CVSS v4.0 8.7 High, with an adjacent-network vector; CISA says it is not remotely exploitable.
- Successful exploitation of CVE-2026-91018 could crash the system, cause denial of service or memory corruption, or lead to code execution.
- Eric Evenchick of Tetrel Security reported CVE-2026-91018.
- CISA says lwIP is deployed across multiple critical infrastructure sectors worldwide.
- CISA reports no known public exploitation of either vulnerability.
Coverage timelineoldest first · each row is one article
- · 5d agolwIP (Lightweight IP)
CISA Advisories· 46
CISA warns lwIP 2.0.1–2.2.1 has a double-free that can crash devices or enable code execution.
- · 5d agolwIP TCP/IP Stack MQTT Client Application
CISA Advisories· 68
CISA warns lwIP MQTT client versions 2.0.1 through 2.2.1 have critical CVE-2026-87121.
Vulnerabilities in this storyAll →
- CVE-2026-871219.3—lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the devicepublished
- CVE-2026-910188.7—Double Free Vulnerability in lwIP Systempublished · lwIP (Lightweight IP)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|