Our takeCISA reports active exploitation in lwIP versions 2.0.1–2.2.1 and its MQTT client app. Patch immediately if you run this stack in embedded or OT devices — same call for enterprises and smaller teams.Cyber Resilience desk
Sources (2)
- cisa_advisories · cisa_advisories
- cisa_advisories · cisa_advisories
What this means for you — Security leader:CISA reports active exploitation in lwIP (CVE-2026-91018, CVSS 8.8) and its MQTT client (CVE-2026-87121, CVSS 9.8) that can lead to DoS, memory corruption, or remote code execution. Update to a fixed version or disable MQTT if you use this stack in any embedded, OT, or networking products.
What this means for you — Lean IT orgs:If any of your devices or IoT gear uses lwIP for networking (common in small industrial controllers or custom hardware), check the vendor for a firmware update right away — these bugs let attackers crash the device or take it over.
What this means for you — MSP:Scan client environments for lwIP 2.0.1–2.2.1 in embedded devices, OT controllers, or custom appliances. Prioritize patching the MQTT client (9.8) and main stack (8.8) — both are under active exploitation per CISA.
What this means for you — Researcher:CISA reports active exploitation of lwIP <=2.2.1 (CVE-2026-91018) and its MQTT client (CVE-2026-87121), enabling DoS, memory corruption, or code execution. Review affected embedded and OT implementations.