The Savannah lwIP SMTP client 2.2.1 suffers a CVE‑2026‑15340 buffer‑overflow that allows remote code execution. Energy and water utilities must patch immediately and prove remediation for audit readiness.
ADTP Breach Watch· October 6, 2026· CISA Advisories
SeverityCritical
Type🐛 Threat intel
ConfidenceHigh
ReportedOct 6, 2026
Energy & UtilitiesEnergy sectorWater and Wastewater sectorVulnerability Exploit
What happened
A classic buffer‑overflow (CWE‑120) in Savannah lwIP SMTP client 2.2.1 fails to check input size, enabling remote attackers to crash the device or execute arbitrary code without authentication.
Why it matters for trust and compliance
The flaw underscores the necessity of continuous vulnerability‑management and patch‑evidence to satisfy control‑assurance requirements across frameworks.
Ensures continuous monitoring of third‑party component versions and patch status.
Provides defensible audit evidence of remediation for control‑assurance reviews.
Who is affected
Energy sectorWater and Wastewater sector
Recommended actions
Apply the vendor‑released patch (patch_125_smtp_txbuf.diff) to all affected devices.
Validate the updated version via inventory scans and document the change.
Integrate automated detection of lwIP library versions into your vulnerability‑management workflow.
Retain patch artifacts and remediation logs as audit‑ready evidence.
Details
CVEs
CVE-2026-15340
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.