CVE-2026-91018

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-415

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-09-22: 309-22
Referenced assets2 URLs
Full discourse3 posts
  • CVE@CVEnew

    CVE-2026-91018 lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system. https://www.cve.org/CVERecord?id=CVE-2026-91018

    00000634
    58.1K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis shows attackers exploiting CVE-2026-91018 double free vulnerability in lwIP to gain initial access to critical infrastructure systems. Memory corruption enables privilege escalation and lateral movement across unencrypted OT networks. Runtime segmentation helps contain post-compromise activity in industrial environments. #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/lwip-double-free-vulnerability-cve-2026-91018-ics

    0000037
    2.0K followersView on X
  • NewsTongue@NewsTongueX

    🔴 Double-free vulnerability in lwIP affects critical infrastructure worldwide A double-free vulnerability in lwIP (Lightweight IP) API versions 2.0.1 through 2.2.1 can crash systems, cause denial of service, corrupt memory, or enable code execution. The flaw (CVE-2026-91018) affects deployments across chemical, energy, financial services, healthcare, transportation, and water systems globally. lwIP is developed in Sweden. Eric Evenchick of Tetrel Security reported the vulnerability to CISA. No public exploitation has been reported.

    0000051
    901 followersView on X

Explore more