ThreatsIndustrial & OTBreakingCritical lwIP MQTT Client Buffer Overflow Enables Remote Code Execution on Industrial IoT Devices CVE-2026-87121CISA releases advisory ICSA-26-265-01 for critical CVSS 9.8 flaw CVE-2026-87121 in lwIP MQTT client, allowing unauthenticated attackers to execute arbitrary code.CST Newsroom·24 Sep 2026, 00:00 IST·16 min read
ThreatsIndustrial & OTBreakingCritical lwIP Embedded TCP/IP Stack Double Free Flaw Exposes Industrial Controllers to Remote Hijacking CVE-2026-91018CISA and lwIP maintainers warn of high-severity flaw CVE-2026-91018 in the lwIP TCP/IP stack allowing unauthenticated remote memory corruption across IoT and PLCs.CST Newsroom·23 Sep 2026, 16:00 IST·16 min read