Critical Out-of-Bounds Write in lwIP MQTT Client Application (CVE-2026-87121) Enables Remote Code Execution
What It Is — The lwIP TCP/IP Stack MQTT Client Application versions 2.0.1 through 2.2.1 contain an out‑of‑bounds write (CVE‑2026‑87121) that can be triggered remotely to achieve full code execution.
Exploitability — CVSS v3.1 base score 9.8 (Critical). Publicly disclosed; proof‑of‑concept code is available; CISA has issued an advisory warning of active exploitation.
Affected Products — lwIP MQTT Client Application (≥ 2.0.1 ≤ 2.2.1) from the lwIP project (nongnu.org).
Why It Matters for Trust & Control Assurance
- Highlights the need for continuous third‑party component inventory and automated vulnerability scanning to satisfy the Vulnerability Management control objective.
- Timely patching creates auditable evidence of due‑diligence, a core requirement for trust‑centric audits across multiple frameworks.
- Unpatched libraries break the defensible audit trail that regulators and enterprise buyers expect from critical‑infrastructure vendors.
Recommended Actions
- Update all lwIP MQTT Client instances to the commit f89407ea711879c04d91c92b35d67be78bbaf0f1 or later.
- Conduct a rapid inventory of devices using the affected stack and verify patch status.
- Integrate CVE‑2026‑87121 into your vulnerability‑management feed and enable continuous monitoring for future releases.
Source: CISA Advisory