CISA issued an advisory on October 6, 2026, warning that the Savannah lwIP SMTP client version 2.2.1 contains a critical buffer overflow vulnerability. Successful exploitation of the flaw could allow remote code execution or crash the targeted device.
Vulnerability Details
According to CISA, the vulnerability stems from the lwIP SMTP client failing to check the size of inputs, creating a classic buffer overflow condition tracked as CVE-2026-15340. The flaw carries a critical CVSS v3 base score of 9.8.
The affected product is deployed worldwide across critical infrastructure sectors including energy, water, and wastewater systems. The company headquarters are located in Sweden.
Remediation and Mitigation
xchglabs reported the vulnerability directly to Savannah and disclosed it after a fix was released. The fix is available in the patch patch_125_smtp_txbuf.diff and as git commit 614420f82c8729d070e01464c0dddb3c9525c772.
CISA recommends that organizations minimize network exposure for all control system devices and isolate them from business networks behind firewalls.
What to do
- Apply the patch patch_125_smtp_txbuf.diff or use git commit 614420f82c8729d070e01464c0dddb3c9525c772.
- Minimize network exposure for all control system devices and systems, ensuring they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolate them from business networks.
- Use secure methods such as virtual private networks (VPNs) when remote access is required, ensuring VPNs are updated to the current version.
Key facts and where they come from
- Savannah lwIP SMTP client version 2.2.1 is affected by CVE-2026-15340.
lwIP SMTP client 2.2.1 (CVE-2026-15340)
- The vulnerability carries a CVSS v3 score of 9.8.
v3 9.8
- Exploitation could crash the device or allow remote code execution.
Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution.
- A patch was released to fix the issue via a specific git commit.
xchglabs reports that the vulnerability was fixed and released in the following patch: patch_125_smtp_txbuf.diff .
