Vendor
critical
advisory
Critical Out-of-Bounds Write in lwIP MQTT Client
An out-of-bounds write vulnerability (CVE-2026-87121) in the lwIP TCP/IP Stack MQTT client allows unauthenticated remote attackers to achieve full code execution on affected devices.
lwIP TCP/IP Stack MQTT Client Application
high
advisory
Double Free Vulnerability in lwIP (Lightweight IP)
The lwIP TCP/IP stack contains a double free vulnerability (CVE-2026-91018) that could allow an attacker with adjacent network access to trigger memory corruption or remote code execution.
lwIP