lwIP (Lightweight IP)
A vulnerability (CVE-2026-91018) exists in lwIP (Lightweight IP) versions 2.0.1 through 2.2.1, potentially leading to system crashes, denial-of-service attacks, or code execution on a victim system. This vulnerability is a double-free and is not exploitable remotely. CISA recommends updating lwIP and implementing network segmentation and secure remote access practices.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory regarding a vulnerability in lwIP (Lightweight IP), a widely used networking library. Specifically, versions 2.0.1 through 2.2.1 are affected. This vulnerability, identified as CVE-2026-91018, is a double-free, which can result in a system crash, denial-of-service, or even allow an attacker to execute code on the victim system. The vulnerability is not exploitable remotely.
This advisory highlights that the affected product is used across a range of critical infrastructure sectors, including Chemical, Communications, Critical Manufacturing, Energy, Financial Services, Healthcare and Public Health, and Transportation Systems. The vulnerability has been reported worldwide.
CISA recommends that users immediately update their lwIP version to a patched version. Additionally, they advise implementing defensive measures such as minimizing network exposure for control system devices, isolating control system networks from business networks, and utilizing secure remote access methods like VPNs (recognizing that VPNs themselves can have vulnerabilities).
CISA also encourages organizations to perform thorough impact analysis and risk assessments before deploying any defensive measures and to implement recommended cybersecurity strategies for proactive defense of Industrial Control Systems (ICS) assets. They provide additional guidance and recommended practices on their ICS webpage at cisa.gov/ics, including a technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.