Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

CVE-2026-54412 is a heap-based out-of-bounds read and integer underflow vulnerability in MQTT-C, an open-source C library used to implement MQTT messaging clients in embedded and IoT systems. A remote attacker controlling or impersonating an MQTT broker can crash any client built on MQTT-C versions through 1.1.6 and potentially read adjacent heap memory, which may contain sensitive application data. Organizations running IoT devices, industrial control systems, or embedded applications that use this library should prioritize identification and patching of affected deployments.

Author

Tech Jacks Solutions