CISA alerts on Savannah lwIP SMTP client buffer overflow (CVE-2026-15340)
Savannah lwIP SMTP client 2.2.1 is vulnerable; patch released 2026-10-06 for energy and water sector devices worldwide.

CISA issued a notice on 2026-10-06 that Savannah lwIP SMTP client version 2.2.1 is affected by CVE-2026-15340, a classic buffer overflow (CWE-120) with a CVSS v3 score of 9.8. Successful exploitation could crash the device or permit remote code execution.
The vulnerability stems from the client's failure to check the size of inputs during a buffer copy operation. The product is listed as known_affected and is deployed worldwide in critical infrastructure sectors, specifically Energy and Water and Wastewater Systems.
Savannah has released a fix in patch_125_smtp_txbuf.diff, available as git commit 614420f82c8729d070e01464c0dddb3c9525c772, which addresses the buffer-overflow condition.
CISA recommends that users minimize network exposure for control-system devices, locate such networks behind firewalls, and employ secure remote-access methods such as up-to-date VPNs. Organizations should conduct impact analyses, follow the recommended practices on the CISA ICS webpage, and consult technical information paper ICS-TIP-12-146-01B for additional mitigation guidance.
Entities observing suspicious activity should follow internal procedures and report findings to CISA for correlation with other incidents.
Further reading

