Critical Double Free Vulnerability in lwIP Networking Stack
CVE-2026-91018 affects lwIP API versions 2.0.1 through 2.2.1, enabling potential code execution and denial of service
Key Takeaways
- CISA has issued advisory icsa-26-265-02 for a critical double free vulnerability in lwIP (CVE-2026-91018).
- Affected versions include lwIP API >=2.0.1 and <=2.2.1.
- Exploitation could result in system crash, DoS, memory corruption, or code execution.
- CVSS v3.1 base score is 8.8; CVSS v4.0 base score is 8.7.
- No known public exploitation has been reported to CISA.
- The vulnerability was reported by Eric Evenchick of Tetrel Security.
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


