Skip to content
Security & Trust

lwIP MQTT client flaw could allow full code execution on affected devices

CISA's advisory lists eight critical infrastructure sectors and points to an upstream fix, not a vendor patch

W
WebPulse Newsroom
AI-assisted · 3 min read
Share on X LinkedIn
lwIP MQTT client flaw could allow full code execution on affected devices
Key finding

Affected MQTT Client Application versions: >=2.0.1 to <=2.2.1 (Source: CISA ICS advisory for CVE-2026-87121)

What CISA published

CISA has issued an ICS advisory for CVE-2026-87121, an out-of-bounds write (CWE-787) in the MQTT client application of the lwIP TCP/IP stack. The advisory says successful exploitation could let an attacker gain full code execution on the device. The researcher Shahriyar Jalayeri of ByteRay Ltd. reported the flaw to CISA. CISA states that no known public exploitation specifically targeting it has been reported to the agency at this time.

>=2.0.1 to <=2.2.1
Affected MQTT Client Application versions
Source: CISA ICS advisory for CVE-2026-87121
8
Critical infrastructure sectors listed in the advisory
Source: CISA ICS advisory for CVE-2026-87121

A component, not a product

The advisory identifies a software component and a version range. In the text reviewed, it does not name end products. That matters for budget-holders, because an asset register may not carry a line for a networking library. The flaw may sit inside supplier firmware rather than in software your team installed directly.

The sector list in the advisory is broad. It runs from chemicals and manufacturing, through energy and water utilities, to communications, transport, finance and healthcare. A shared library can turn up in very different kinds of equipment, so exposure is a question for each estate, not for each industry.

The fix sits upstream

CISA's mitigation guidance directs lwIP users to the project repository on Savannah and names the commit that contains the fix. Organisations that build their own firmware can act on that directly. Those that buy equipment depend on their suppliers to pull the change into a release. The advisory does not describe how or when suppliers will do so, so the timeline is a question for each supplier.

f89407ea711879c04d91c92b35d67be78bbaf0f1
Fix commit identifier
Source: CISA ICS advisory for CVE-2026-87121

Controls CISA lists while updates are pending

CISA's general ICS guidance applies here. Its first recommendation is to keep control system devices off the internet. It also calls for segmentation: operational networks and remote endpoints should sit behind a firewall, apart from the corporate IT environment. Where remote access is needed, CISA suggests VPNs, with the caveat that VPNs may have vulnerabilities and that a VPN is "only as secure as the connected devices." CISA also reminds organisations to run an impact analysis and risk assessment before deploying defensive measures.

Questions to put to your team

1. Which devices in our operational and connected-equipment estate embed lwIP, and at which version? Can each supplier confirm this in writing?

2. Do any of those devices use the MQTT client application, and do any fall between versions 2.0.1 and 2.2.1?

3. Which affected devices can be reached from the internet, or from our business network, today?

4. For each one, who applies the fix (us or the supplier), and what release date has the supplier committed to?

5. Where a device cannot be updated soon, what isolation is in place, and has the impact analysis CISA recommends been completed?

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.

CVEs in this analysis
CVE-2026-87121
Share this insight