lwIP - Multiple Severe Vulnerabilities
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-87121, CVE-2026-91018, Summary: Two memory-safety vulnerabilities affect lwIP versions 2.0.1–2.2.1. CVE-2026-87121 is an out-of-bounds write in the MQTT client that could allow an unauthenticated network attacker to execute code on an affected device. CVE-2026-91018 is an adjacent-network double-free vulnerability that could cause denial of service, memory corruption or code execution…
EPSS 0.01 CVSS 9.8 CVE-2026-87121 CVE-2026-91018 lwIP FI