CVE-2026-91018

lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.

  • Published Sep 22, 2026
  • CVSS 8.7 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-91018 at the National Vulnerability Database