CVE-2026-87121: Lwip Tcp/ip Stack Mqtt

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

Affected products

  • Lwip Tcp/ip Stack Mqtt: from 2.0.1, up to and including 2.2.1

Published 2026-09-22. Last modified 2026-09-23.