MajorCritical vulnerability
CVE-2026-91018 (CVSS 8.7)
NVD · officialPublished Sep 22, 2026Risk 37/100EPSS 0.2%
lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.
Technical details
CVSS
8.7
AV:AdjacentAC:LowPR:NoneUI:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source