CVE-2026-8836Disclosure

LOWCVSS 8.9 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow. The attack may be initiated remotely. The patch is named 0c957ec03054eb6c8205e9c9d1d05d90ada3898c. It is suggested to install a patch to address this issue. Two separate issue reports were submitted to the project. Their processing was merged as a duplicate.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-05-18); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-05-18: 2Mentions · 2026-05-19: 1Mentions · 2026-05-20: 2Mentions · 2026-06-12: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-06-12: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-20: 1Technical Details · 2026-06-12: 105-1805-1905-2006-12
Signal classification3 categories
Disclosure
233.3%
Patch
233.3%
General
233.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-182
Disclosure1Patch1
2026-05-191
General1
2026-05-202
Disclosure1General1
2026-06-121
Patch1
Full discourse6 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-8836 — CVSS 9.8/10 ██████████ A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/umGbaWcBd2

    Post summary

    CVE-2026-8836 identified as a critical flaw in lwIP (snmp_parse_inbound_frame) with a CVSS score of 9.8. A patch has already been released.

    10000129
    42 followersView on X
  • ThreatCluster@threatcluster
    Patch

    Ubuntu released USN-8423-1 fixing multiple lwIP flaws, including buffer overflows in EAP auth and SNMPv3 (CVE-2020-8597, CVE-2026-8836) affecting Ubuntu 20.04, 22.04, 24.04 and 26.04 LTS, Ubuntu security notice said. https://threatcluster.io/cluster/multiple-lwip-vulnerabilities-affecting-ubuntu-2004-lts-583cddc9

    Post summary

    Ubuntu’s USN-8423-1 patch addresses buffer overflow flaws in lwIP’s EAP auth and SNMPv3 on multiple LTS releases, with no evidence of active exploitation or PoC reported.

    0000054
    330 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-8836 A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handle… https://www.cve.org/CVERecord?id=CVE-2026-8836 ----- Traducción: CVE-2026-8836 Se … http://infoflow.cloud`

    Post summary

    The message surfaces CVE‑2026‑8836 with a brief reference to the affected function in lwIP, but offers no detail on exploitation, fixes, or technical aspects.

    0000051
    78 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8836 A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handle… https://www.cve.org/CVERecord?id=CVE-2026-8836

    Post summary

    An update to lwIP reveals a flaw in the SNMPv3 USM component, specifically the snmp_parse_inbound_frame function, but no exploit code, active exploitation, or patch information is discussed.

    00000315
    57.5K followersView on X
  • VulDB 🛡@vuldb
    General

    Some increased actor activities are shown targeting lwIP (CVE-2026-8836) https://vuldb.com/vuln/364474/cti

    Post summary

    The post notes observed actor activity targeting the lwIP vulnerability CVE‑2026‑8836 but does not provide any proof‑of‑concept, exploit, patch, or confirmation of active exploitation.

    0000073
    2.2K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting lwIP (CVE-2026-8836) https://vuldb.com/vuln/364474

    Post summary

    A new vulnerability (CVE‑2026‑8836) affecting lwIP has been reported, with severity noted as increased; minimal details are provided.

    0000089
    2.2K followersView on X

Explore more