Cyber Resilience
← All news
Confirmed

lwIP (Lightweight IP)

Our takeCISA reports active exploitation of two high-severity flaws in lwIP (including its MQTT client) that can lead to DoS, memory corruption, or full code execution. Patch affected versions immediately — same urgency for OT operators of any size and enterprise users alike.
Sources (2)
What this means for you — Security leader:CISA reports active exploitation of two high-severity vulnerabilities (CVSS 8.8 and 9.8) in lwIP and its MQTT client (v2.0.1–2.2.1) that can lead to DoS, memory corruption, or remote code execution. Update to a fixed version or disable MQTT if unneeded; treat as emergency patching for any OT/embedded systems using this stack.
What this means for you — Lean IT orgs:If your devices, routers, or IoT gear run lwIP (common in lightweight embedded TCP/IP), this CISA advisory means remote code execution is possible. Check vendor firmware updates today and apply them — most small teams can do this through the device admin interface or by contacting the maker.
What this means for you — MSP:Scan client environments for lwIP 2.0.1–2.2.1 in routers, IoT, industrial controllers, or custom embedded devices. Push firmware updates immediately per the two CISA ICS advisories; this affects both general TCP/IP and MQTT client paths across many vendors.
What this means for you — Researcher:CISA confirms active exploitation of CVE-2026-91018 (lwIP core) and CVE-2026-87121 (MQTT client) leading to RCE. Both affect versions >=2.0.1 <=2.2.1; see the linked ICS advisories for exact impact and mitigations.