Executive Summary
A critical out-of-bounds write vulnerability (CVE-2026-87121) was discovered in the lwIP TCP/IP Stack MQTT Client Application versions 2.0.1 through 2.2.1, affecting industrial control systems across multiple critical infrastructure sectors worldwide. The vulnerability carries a CVSS score of 9.8 and enables remote attackers to achieve full code execution without authentication, potentially compromising devices in chemical, energy, healthcare, transportation, and water systems. The flaw was discovered by Shahriyar Jalayeri of ByteRay Ltd. and reported to CISA, with fixes available through the lwIP repository.
This vulnerability highlights the growing threat landscape facing industrial IoT devices and embedded systems, as attackers increasingly target foundational networking components to gain persistent access to critical infrastructure networks.
Why This Matters Now
Critical infrastructure attacks are escalating globally, and this vulnerability in a widely-deployed TCP/IP stack demonstrates how foundational networking components can become single points of failure across multiple sectors simultaneously.
Attack Path Analysis
Attackers exploit CVE-2026-87121, an out-of-bounds write vulnerability in lwIP MQTT Client Application to gain initial code execution on IoT/ICS devices. From the compromised device, attackers escalate privileges to gain administrative control, move laterally across unencrypted industrial networks to compromise additional systems, establish command and control channels over unmonitored egress traffic, exfiltrate sensitive operational data and intellectual property, and ultimately disrupt critical infrastructure operations causing service outages and safety concerns.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Exploitation of CVE-2026-87121 out-of-bounds write vulnerability in lwIP MQTT Client Application versions 2.0.1-2.2.1 to achieve remote code execution on exposed industrial devices
Related CVEs
CVE-2026-87121
CVSS 9.8An out-of-bounds write vulnerability in lwIP TCP/IP Stack MQTT Client Application versions 2.0.1 through 2.2.1 allows an attacker to gain full code execution on the device.
Affected Products:
lwIP lwIP TCP/IP Stack MQTT Client Application – >=2.0.1, <=2.2.1
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Privilege Escalation
Process Injection
Exploitation for Client Execution
Valid Accounts
Data Encrypted for Impact
Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Vulnerability Management Process
Control ID: 6.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.10
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Asset Management
Control ID: Identity.AM-1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21(2)(a)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Utilities
Critical infrastructure vulnerability in lwIP TCP/IP stack affects SCADA systems, enabling remote code execution with potential for operational disruption and safety incidents.
Oil/Energy/Solar/Greentech
Energy sector's industrial control systems using lwIP MQTT clients face critical remote exploitation risks, threatening grid stability and production facility operations.
Chemical
Chemical manufacturing processes rely on vulnerable TCP/IP stacks for sensor communication, creating severe safety risks through potential unauthorized control system access.
Water and Wastewater Systems
Water infrastructure monitoring systems using affected lwIP implementations vulnerable to remote attacks, potentially compromising treatment processes and public health safety.
Sources
- lwIP TCP/IP Stack MQTT Client Applicationhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-265-01Verified
- lwIP Official Repositoryhttps://savannah.nongnu.org/projects/lwipVerified
- CWE-787: Out-of-bounds Writehttps://cwe.mitre.org/data/definitions/787.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this IoT/ICS attack by segmenting industrial networks and enforcing granular east-west traffic policies. The comprehensive segmentation approach could significantly reduce lateral movement opportunities and limit the attacker's ability to reach critical infrastructure systems across the industrial environment.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The initial compromise of IoT devices would likely still occur, but CNSF visibility and monitoring could reduce the time to detection and limit the attacker's ability to establish persistent footholds across multiple device endpoints.
Control: Zero Trust Segmentation
Mitigation: Administrative privilege escalation may still succeed on the compromised device, but zero trust segmentation would likely constrain the scope of elevated access and reduce the attacker's ability to leverage administrative privileges for broader network reconnaissance.
Control: East-West Traffic Security
Mitigation: Lateral movement between industrial systems would likely be significantly constrained by microsegmentation policies that restrict device-to-device communications and enforce identity-based access controls across the industrial network infrastructure.
Control: Multicloud Visibility & Control
Mitigation: Command and control establishment would likely be constrained through enhanced visibility into network communications patterns and anomaly detection that could identify suspicious outbound connections from industrial devices to external infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be significantly reduced through controlled egress policies that restrict outbound data flows from industrial devices and enforce inspection of external communications containing sensitive operational information.
While infrastructure disruption risk would likely be reduced through network segmentation, attackers may still cause localized service impacts within the scope of their constrained access to individual compromised devices or isolated network segments.
Impact at a Glance
Affected Business Functions
- Industrial Control Systems
- Network Communications
- Device Management
- Remote Monitoring
Estimated downtime: 7 days
Estimated loss: N/A
Potential compromise of industrial control systems and IoT devices using lwIP stack, with possible unauthorized access to operational technology networks and device control capabilities
Recommended Actions
Key Takeaways & Next Steps
- • Implement Inline IPS (Suricata) capabilities to detect and block exploit attempts targeting known CVEs like CVE-2026-87121 before they achieve code execution
- • Deploy Zero Trust Segmentation with microsegmentation policies to prevent lateral movement between industrial devices and limit blast radius of compromised endpoints
- • Enable Encrypted Traffic (HPE) controls with MACsec and IPsec to protect data in transit across industrial networks and prevent credential theft during lateral movement
- • Configure Egress Security & Policy Enforcement with FQDN filtering to block unauthorized outbound communications and prevent command & control establishment
- • Establish Multicloud Visibility & Control with centralized monitoring to detect anomalous interactions and repeated malformed requests targeting vulnerable applications across hybrid industrial environments



