Government Advisory

Critical Flaw Found in Widely Used lwIP Network Software MQTT Client

CISA · 22 Sept 2026
Key Takeaway Check with the vendors of any network-connected or IoT devices you use to see if they rely on lwIP and have released a security update addressing this flaw.

CISA has issued an advisory for lwIP, an open-source TCP/IP networking library used in a huge range of embedded and IoT devices across industries including energy, healthcare, communications, manufacturing and water systems. The flaw, tracked as CVE-2026-87121, sits in the MQTT client component (versions 2.0.1 to 2.2.1) and carries a near-maximum severity score of 9.8 out of 10.

The vulnerability is an out-of-bounds write, a type of bug that lets an attacker corrupt memory in ways that can lead to full code execution on the device. Because lwIP is embedded deep inside countless network-connected products, from industrial controllers to consumer smart devices, the practical risk depends heavily on which specific products a business uses and whether those vendors have shipped a fix.

There is no indication in this advisory of active exploitation, but the severity score means it should be treated as a priority. CISA recommends updating to a fixed version of lwIP via the project's official repository, which vendors using this library will need to incorporate into their own product updates.

lwIP CISA advisory IoT security critical vulnerability MQTT

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.