Vulnerability record

CVE-2026-91018

Severity: HighExploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Description

lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-91018 scored CVSS 8.7

    Basis: NIST National Vulnerability Database

  2. Disclosed

    lwIP (Lightweight IP)

    Basis: CISA Cybersecurity Advisories (government advisory)

Coverage

Severity: HighAction: Mitigate

lwIP (Lightweight IP)

Mitigate

No complete fix is indicated yet.

References

  • cgit.git.savannah.gnu.org https://cgit.git.savannah.gnu.org/cgit/lwip.git
  • github.com https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-02.json
  • cisa.gov https://www.cisa.gov/news-events/ics-advisories/icsa-26-265-02