Vulnerability record

CVE-2026-87121

Severity: CriticalExploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Description

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-87121 scored CVSS 9.3

    Basis: NIST National Vulnerability Database

  2. Disclosed

    lwIP TCP/IP Stack MQTT Client Application

    Basis: CISA Cybersecurity Advisories (government advisory)

Coverage

References

  • github.com https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-01.json
  • savannah.nongnu.org https://savannah.nongnu.org/projects/lwip
  • cisa.gov https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-01