Critical Buffer Overflow Vulnerability in Savannah lwIP SMTP Client Allows RCE
CISA has issued an advisory for CVE-2026-15340, a critical buffer overflow vulnerability in Savannah's lwIP SMTP client version 2.2.1, which could lead to remote code execution.

CISA has alerted organizations to a critical vulnerability, tracked as CVE-2026-15340, affecting version 2.2.1 of Savannah's lwIP SMTP client. This vulnerability, classified as a buffer overflow without proper input size checking, poses a significant risk to industrial control systems (ICS) across various critical infrastructure sectors.
The vulnerability stems from the lwIP SMTP client's failure to validate the size of incoming data before processing it. This oversight can lead to a buffer overflow condition, where an attacker can overwrite adjacent memory regions. Successful exploitation could result in the disruption of device operations through crashes or, more severely, allow for remote code execution (RCE) on the affected system.
The Common Vulnerability Scoring System (CVSS) v3.1 base score for this vulnerability is a critical 9.8, with a CVSS v4.0 score of 9.3. These high scores reflect the potential for widespread impact and the ease of exploitation, as the attack vector is network-based (AV:N), requires low complexity (AC:L), and needs no privileges (PR:N) or user interaction (UI:N).
Savannah's lwIP SMTP client 2.2.1 is known to be affected. The vulnerability has been reported as deployed worldwide, impacting critical infrastructure sectors such as Energy and Water and Wastewater Systems. The vendor, Savannah, is headquartered in Sweden.
Fortunately, a patch has been developed and released by xchglabs, the researchers who reported the vulnerability to Savannah. The fix is available via a git commit identified as 614420f82c8729d070e01464c0dddb3c9525c772. Organizations are strongly advised to apply this patch as soon as possible to mitigate the risk.
CISA recommends several defensive measures to minimize the risk of exploitation. These include minimizing network exposure of control system devices, ensuring they are not directly accessible from the internet, and locating them behind firewalls and isolated from business networks. When remote access is necessary, the use of secure methods like VPNs is advised, with the caveat that VPNs themselves must be kept updated and secure.
Organizations are encouraged to perform thorough impact and risk assessments before implementing any defensive measures. CISA also points to its resources on ICS cybersecurity, including best practices for defense-in-depth strategies and targeted cyber intrusion detection and mitigation, available on its website.
This advisory serves as a critical reminder of the ongoing threats to industrial control systems and the importance of timely patching and robust network segmentation to protect essential services.