CVE-2026-87121

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

  • Published Sep 22, 2026
  • CVSS 9.3 critical
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-87121 at the National Vulnerability Database