Affected MQTT Client Application versions: >=2.0.1 to <=2.2.1 (Source: CISA ICS advisory for CVE-2026-87121)
What CISA published
CISA has issued an ICS advisory for CVE-2026-87121, an out-of-bounds write (CWE-787) in the MQTT client application of the lwIP TCP/IP stack. The advisory says successful exploitation could let an attacker gain full code execution on the device. The researcher Shahriyar Jalayeri of ByteRay Ltd. reported the flaw to CISA. CISA states that no known public exploitation specifically targeting it has been reported to the agency at this time.
A component, not a product
The advisory identifies a software component and a version range. In the text reviewed, it does not name end products. That matters for budget-holders, because an asset register may not carry a line for a networking library. The flaw may sit inside supplier firmware rather than in software your team installed directly.
The sector list in the advisory is broad. It runs from chemicals and manufacturing, through energy and water utilities, to communications, transport, finance and healthcare. A shared library can turn up in very different kinds of equipment, so exposure is a question for each estate, not for each industry.
The fix sits upstream
CISA's mitigation guidance directs lwIP users to the project repository on Savannah and names the commit that contains the fix. Organisations that build their own firmware can act on that directly. Those that buy equipment depend on their suppliers to pull the change into a release. The advisory does not describe how or when suppliers will do so, so the timeline is a question for each supplier.
Controls CISA lists while updates are pending
CISA's general ICS guidance applies here. Its first recommendation is to keep control system devices off the internet. It also calls for segmentation: operational networks and remote endpoints should sit behind a firewall, apart from the corporate IT environment. Where remote access is needed, CISA suggests VPNs, with the caveat that VPNs may have vulnerabilities and that a VPN is "only as secure as the connected devices." CISA also reminds organisations to run an impact analysis and risk assessment before deploying defensive measures.
Questions to put to your team
1. Which devices in our operational and connected-equipment estate embed lwIP, and at which version? Can each supplier confirm this in writing?
2. Do any of those devices use the MQTT client application, and do any fall between versions 2.0.1 and 2.2.1?
3. Which affected devices can be reached from the internet, or from our business network, today?
4. For each one, who applies the fix (us or the supplier), and what release date has the supplier committed to?
5. Where a device cannot be updated soon, what isolation is in place, and has the impact analysis CISA recommends been completed?
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.





