Critical Flaw Found in Widely Used lwIP Network Software MQTT Client
CISA has issued an advisory for lwIP, an open-source TCP/IP networking library used in a huge range of embedded and IoT devices across industries including energy, healthcare, communications, manufacturing and water systems. The flaw, tracked as CVE-2026-87121, sits in the MQTT client component (versions 2.0.1 to 2.2.1) and carries a near-maximum severity score of 9.8 out of 10.
The vulnerability is an out-of-bounds write, a type of bug that lets an attacker corrupt memory in ways that can lead to full code execution on the device. Because lwIP is embedded deep inside countless network-connected products, from industrial controllers to consumer smart devices, the practical risk depends heavily on which specific products a business uses and whether those vendors have shipped a fix.
There is no indication in this advisory of active exploitation, but the severity score means it should be treated as a priority. CISA recommends updating to a fixed version of lwIP via the project's official repository, which vendors using this library will need to incorporate into their own product updates.