CISA, the US cyber agency, published an advisory on 6 October 2026 about a flaw in the Savannah lwIP SMTP client. SMTP is the standard way software sends email. CISA said a successful attack could crash the device. The overflow may also let an attacker run their own code from a distance. CISA lists energy and water and wastewater systems as the affected sectors. It says xchglabs reported the flaw to Savannah privately and went public once a fix was out. According to xchglabs, the fix is a patch file named patch_125_smtp_txbuf.diff, also available as a git commit.
CISA labels the weakness CWE-120, a classic buffer overflow. A program copies data into a space without first checking that the data fits. The extra data spills past the end of that space. That is how a crash or remote code execution can follow. For the list of affected versions and any severity details, readers should consult CISA advisory ICSA-26-279-02.
Email-sending code can be a small part of a device's software, and it may not show up in an asset list. Operators can ask whether their device firmware includes this client and who is responsible for patching it. CISA also tells operators to keep control systems off the internet and behind firewalls, apart from business networks. It adds that VPNs, used for remote access, can have flaws of their own.