# Out-of-bounds write flaw in lwIP MQTT client

Published: 2026-09-22 · Severity: routine · Sectors: energy, healthcare, transportation, financial-services, infrastructure, manufacturing, telecommunications
Canonical: https://vorant.io/reports/f9d315ba-84c7-5990-8c1a-4a1f454b2b2a/out-of-bounds-write-flaw-in-lwip-mqtt-client

> An out-of-bounds write in lwIP's MQTT client (versions 2.0.1-2.2.1) could let an attacker achieve full code execution on affected embedded devices; no known exploitation in the wild.

CISA has published an ICS advisory for a vulnerability in the MQTT Client Application component of the lwIP TCP/IP stack, a widely embedded networking library used across critical infrastructure sectors including chemical, communications, critical manufacturing, energy, financial services, healthcare, transportation, and water/wastewater. The vulnerability, tracked as CVE-2026-87121 and classified as CWE-787 (Out-of-bounds Write), affects lwIP MQTT Client versions >=2.0.1 and <=2.2.1. Successful exploitation could allow an attacker to achieve full code execution on the affected device, which is significant given lwIP's broad deployment in embedded and IoT/ICS devices worldwide.

The vulnerability was reported to CISA by Shahriyar Jalayeri of ByteRay Ltd. CISA states no known public exploitation specifically targeting this vulnerability has been reported at this time. A fix is available upstream via the lwIP repository on Savannah, identified by commit f89407ea711879c04d91c92b35d67be78bbaf0f1.

Defenders and device manufacturers using lwIP's MQTT client should update to the patched version referencing the fix commit. Standard ICS network hardening practices apply: minimize internet exposure of control system devices, isolate control networks behind firewalls, and use VPNs with up-to-date patching for any required remote access. Given the wide deployment of lwIP embedded in numerous vendor products, asset owners should inventory devices for use of this library and coordinate patching with device vendors.

## Mentioned in this report

- Vulnerabilities: CVE-2026-87121

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-01

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f9d315ba-84c7-5990-8c1a-4a1f454b2b2a/out-of-bounds-write-flaw-in-lwip-mqtt-client.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
