HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Out-of-Bounds Write in lwIP MQTT Client Application (CVE-2026-87121) Enables Remote Code Execution

The lwIP MQTT Client Application (v2.0.1‑v2.2.1) contains a CVE‑2026‑87121 out‑of‑bounds write that can grant attackers full code execution. The flaw underscores the importance of robust third‑party component monitoring and patch evidence for audit readiness.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
cisa.gov

Critical Out-of-Bounds Write in lwIP MQTT Client Application (CVE-2026-87121) Enables Remote Code Execution

What It Is — The lwIP TCP/IP Stack MQTT Client Application versions 2.0.1 through 2.2.1 contain an out‑of‑bounds write (CVE‑2026‑87121) that can be triggered remotely to achieve full code execution.

Exploitability — CVSS v3.1 base score 9.8 (Critical). Publicly disclosed; proof‑of‑concept code is available; CISA has issued an advisory warning of active exploitation.

Affected Products — lwIP MQTT Client Application (≥ 2.0.1 ≤ 2.2.1) from the lwIP project (nongnu.org).

Why It Matters for Trust & Control Assurance

  • Highlights the need for continuous third‑party component inventory and automated vulnerability scanning to satisfy the Vulnerability Management control objective.
  • Timely patching creates auditable evidence of due‑diligence, a core requirement for trust‑centric audits across multiple frameworks.
  • Unpatched libraries break the defensible audit trail that regulators and enterprise buyers expect from critical‑infrastructure vendors.

Recommended Actions

  1. Update all lwIP MQTT Client instances to the commit f89407ea711879c04d91c92b35d67be78bbaf0f1 or later.
  2. Conduct a rapid inventory of devices using the affected stack and verify patch status.
  3. Integrate CVE‑2026‑87121 into your vulnerability‑management feed and enable continuous monitoring for future releases.

Source: CISA Advisory

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-01

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →