lwIP (Lightweight IP)
CISA warns lwIP 2.0.1–2.2.1 has a double-free that can crash devices or enable code execution.
CISA ICS advisory ICSA-26-265-02 covers CVE-2026-91018, a double-free (CWE-415) in lwIP API versions 2.0.1 through 2.2.1. Successful exploitation could crash the system, cause a denial of service or memory corruption, or lead to code execution. CVSS v3.1 is 8.8 High and CVSS v4.0 is 8.7 High, with an adjacent-network vector; CISA says it is not remotely exploitable. Eric Evenchick of Tetrel Security reported it, and CISA says no known public exploitation has been reported.
- CVE-2026-91018 is a double-free in lwIP API 2.0.1 through 2.2.1.
- CVSS v3.1 is 8.8 High; the flaw is adjacent-network, not remote.
- Impact can include crash, denial of service, memory corruption, or code execution.
- CISA reports no known public exploitation of this vulnerability.
Vulnerabilities mentionedAll →
- CVE-2026-910188.7—Double Free Vulnerability in lwIP Systempublished · lwIP (Lightweight IP)
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91018 | Double Free Vulnerability in lwIP System The CVE-2026-91018 vulnerability in lwIP exposes a double free flaw, which can cause system crashes, denial of service, memory corruption, or allow code execution on the victim system. The vulnerability has no known public exploit and no CISA KEV classification, indicating it is currently under active monitoring but not actively exploited. Do: Upgrade to the latest stable version of lwIP to patch the double free vulnerability. Implement memory sanitization and memory allocation validation checks. Monitor for abnormal system behavior and verify no unpatched installations remain. |
Full article496 words · extracted from cisa.gov · click to collapse
Summary
Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system.
The following versions of lwIP (Lightweight IP) are affected:
- API >=2.0.1|<=2.2.1 (CVE-2026-91018)
| CVSS | Vendor | Equipment | Vulnerabilities |
|---|---|---|---|
| v3 8.8 | lwIP | lwIP (Lightweight IP) | Double Free |
Background
- Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Energy, Financial Services, Healthcare and Public Health, Transportation Systems, Water and Wastewater Systems
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: Sweden
Vulnerabilities
CVE-2026-91018
The affected product has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.
Affected Products
lwIP (Lightweight IP)
Vendor:
lwIP
Product Version:
lwIP API: >=2.0.1|<=2.2.1
Product Status:
known_affected
Relevant CWE: CWE-415 Double Free
Metrics
| CVSS Version | Base Score | Base Severity | Vector String |
|---|---|---|---|
| 3.1 | 8.8 | HIGH | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 4.0 | 8.7 | HIGH | CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Acknowledgments
- Eric Evenchick of Tetrel Security reported this vulnerability to CISA.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability.
- Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
- Locate control system networks and remote devices behind firewalls and isolating them from business networks.
- When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves from social engineering attacks:
- Do not click web links or open attachments in unsolicited email messages.
- Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
- Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.
No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely.
Revision History
- Initial Release Date: 2026-09-22
| Date | Revision | Summary |
|---|---|---|
| 2026-09-22 | 1 | Initial Publication |