Severity: CriticalAction: Mitigate
lwIP TCP/IP Stack MQTT Client Application
Mitigate
No complete fix is indicated yet.
No official fix confirmed yet
Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.
lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
Developments from the last 30 days, newest first.
CVE-2026-87121 scored CVSS 9.3
Basis: NIST National Vulnerability Database
lwIP TCP/IP Stack MQTT Client Application
Basis: CISA Cybersecurity Advisories (government advisory)
No complete fix is indicated yet.