Users are strongly encouraged to update lwIP to a version beyond 2.2.1. The fix is available in the upstream repository at https://cgit.git.savannah.gnu.org/cgit/lwip.git with commit identifier f873b6295933e4149a2132adf3e9a2d2a676a5ec. Minimize network exposure for control system devices and ensure systems are not accessible from the internet. Use VPNs for remote access where required, keeping devices and VPN software updated.
Quick answers
What is CVE-2026-91018?
Users are strongly encouraged to update lwIP to a version beyond 2.2.1. The fix is available in the upstream repository at https://cgit.git.savannah.gnu.org/cgit/lwip.git with commit identifier f873b6295933e4149a2132adf3e9a2d2a676a5ec. Minimize network exposure for control system devices and ensure systems are not accessible from the internet. Use VPNs for remote access where required, keeping devices and VPN software updated.
How severe is CVE-2026-91018?
high, CVSS 8.8
Is CVE-2026-91018 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-91018 be mitigated?
Users are strongly encouraged to update lwIP to a version beyond 2.2.1. The fix is available in the upstream repository at https://cgit.git.savannah.gnu.org/cgit/lwip.git with commit identifier f873b6295933e4149a2132adf3e9a2d2a676a5ec. Minimize network exposure for control system devices and ensure systems are not accessible from the internet. Use VPNs for remote access where required, keeping devices and VPN software updated.
CVSS
8.8
Vendor
lwIP
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
lwIP (Lightweight IP)
Mitigation
Users are strongly encouraged to update lwIP to a version beyond 2.2.1. The fix is available in the upstream repository at https://cgit.git.savannah.gnu.org/cgit/lwip.git with commit identifier f873b6295933e4149a2132adf3e9a2d2a676a5ec. Minimize network exposure for control system devices and ensure systems are not accessible from the internet. Use VPNs for remote access where required, keeping devices and VPN software updated.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory regarding a critical double free vulnerability in the lwIP (Lightweight IP) networking stack. Exploitation could result in system crashes, denial of service, memory corruption, or code execution on the victim system. The vulnerability affects lwIP API versions from 2.0.1 to 2.2.1. Eric Evenchick of Tetrel Security reported the flaw to CISA. No known public exploitation has been reported at this time.