Cyber Resilience
← All news
Confirmed

lwIP (Lightweight IP)

Our takeCISA reports active exploitation in lwIP versions 2.0.1–2.2.1 and its MQTT client app. Patch immediately if you run this stack in embedded or OT devices — same call for enterprises and smaller teams.
Sources (2)
What this means for you — Security leader:CISA reports active exploitation in lwIP (CVE-2026-91018, CVSS 8.8) and its MQTT client (CVE-2026-87121, CVSS 9.8) that can lead to DoS, memory corruption, or remote code execution. Update to a fixed version or disable MQTT if you use this stack in any embedded, OT, or networking products.
What this means for you — Lean IT orgs:If any of your devices or IoT gear uses lwIP for networking (common in small industrial controllers or custom hardware), check the vendor for a firmware update right away — these bugs let attackers crash the device or take it over.
What this means for you — MSP:Scan client environments for lwIP 2.0.1–2.2.1 in embedded devices, OT controllers, or custom appliances. Prioritize patching the MQTT client (9.8) and main stack (8.8) — both are under active exploitation per CISA.
What this means for you — Researcher:CISA reports active exploitation of lwIP <=2.2.1 (CVE-2026-91018) and its MQTT client (CVE-2026-87121), enabling DoS, memory corruption, or code execution. Review affected embedded and OT implementations.