How do I determine whether a product uses lwIP API versions 2.0.1 through 2.2.1?

If you own or manage a product that may include lwIP, the key question is whether it uses lwIP API versions 2.0.1 through 2.2.1.
The version range to look for
CISA advisory ICSA-26-265-02 covers CVE-2026-91018, a double-free vulnerability affecting lwIP API versions:
- 2.0.1 through 2.2.1
That version range is the exposure check. If the product uses a different version, the advisory context provided here does not confirm that it is affected by this CVE.
How to verify it in practice
For embedded products, lwIP may not be visible in a normal user interface. A practical check usually starts with the product’s own technical documentation, software bill of materials, firmware notes, or vendor security notice.
You need one confirmed answer: does this product include lwIP API version 2.0.1, 2.0.2, later 2.0.x, 2.1.x, or up through 2.2.1?
The context does not provide a universal command, file path, or device menu for checking lwIP. Avoid guessing based on product category alone.
Why this matters
CISA says exploitation of CVE-2026-91018 could crash a system, cause denial of service, corrupt memory, or lead to code execution on the victim system.
The advisory also notes worldwide deployment and lists affected technology across several critical infrastructure sectors.
What to do if you cannot confirm
If you cannot determine the embedded TCP/IP stack version from your own records, check the official CISA advisory and the product vendor’s security information. Advisory details can change, so use the official page when documenting exposure.
What should device owners do after CISA advisory ICSA-26-265-02 for lwIP?

CISA advisory ICSA-26-265-02 should prompt device owners to check whether their products use affected lwIP API versions, especially where devices support critical operations.
First action: identify affected use
CISA says CVE-2026-91018 affects lwIP API versions 2.0.1 through 2.2.1.
Device owners should start by identifying products that use lwIP, also known as Lightweight IP, and then confirm whether the version falls in that range.
For many products, that may require vendor documentation or a vendor security notice, because lwIP can be embedded inside device firmware.
Why the advisory is important
CISA describes CVE-2026-91018 as a double-free vulnerability. According to the advisory context, exploitation could result in:
- System crash
- Denial of service
- Memory corruption
- Code execution on the victim system
CISA assigns the issue a CVSS v3 score of 8.8.
Sectors CISA says are relevant
The affected technology is listed across several critical infrastructure sectors, including:
- Chemical
- Communications
- Critical manufacturing
- Energy
- Financial services
- Healthcare and public health
- Transportation
- Water and wastewater
This does not mean every device in those sectors is affected. It means products using the affected lwIP API versions deserve review.
Keep the check tied to official information
The provided context does not include a product-by-product fix list. Before marking remediation complete, compare your product details with CISA’s advisory and the relevant vendor’s latest information.
Which lwIP issue is more urgent: CVE-2026-91018 or CVE-2026-87121?
Both lwIP-related issues deserve investigation. The more urgent one for your environment depends on which technology your device actually uses.
Quick comparison
| Item | CVE-2026-91018 | CVE-2026-87121 |
|---|---|---|
| CISA advisory date | September 22, 2026 | September 22, 2026 |
| Advisory | ICSA-26-265-02 | Separate lwIP TCP/IP Stack MQTT Client Application advisory |
| Vulnerability type | Double-free vulnerability | Out-of-bounds write |
| Confirmed affected scope in context | lwIP API versions 2.0.1 through 2.2.1 | lwIP TCP/IP Stack MQTT Client Application |
| Possible impact described | Crash, denial of service, memory corruption, or code execution | May allow full code execution on a device |
How to prioritize
Start with asset matching, not the CVE number alone.
If your product uses lwIP API versions 2.0.1 through 2.2.1, CVE-2026-91018 is directly relevant based on the CISA advisory context. CISA gives that issue a CVSS v3 score of 8.8 and notes worldwide deployment.
If your product uses the lwIP TCP/IP Stack MQTT Client Application, then CVE-2026-87121 also needs review because CISA describes it as an out-of-bounds write that may allow full code execution on a device.
What not to assume
The context does not say that one CVE is universally more urgent for every environment. A device affected by one issue and not the other should be prioritized based on confirmed exposure.
Check the official CISA advisories for the latest affected-product and mitigation details before closing an investigation.
What is the September 22, 2026 timeline for the lwIP CISA advisories?

CISA published two lwIP-related ICS advisories on September 22, 2026. They cover different vulnerabilities and should be tracked separately.
Timeline
| Date | Advisory activity |
|---|---|
| September 22, 2026 | CISA published ICSA-26-265-02 for lwIP, covering CVE-2026-91018. |
| September 22, 2026 | CISA also published a separate advisory for the lwIP TCP/IP Stack MQTT Client Application, covering CVE-2026-87121. |
What each advisory covered
ICSA-26-265-02 covers CVE-2026-91018, a double-free vulnerability affecting lwIP API versions 2.0.1 through 2.2.1. CISA says exploitation could crash a system, cause denial of service, corrupt memory, or lead to code execution.
The separate lwIP TCP/IP Stack MQTT Client Application advisory covers CVE-2026-87121. CISA describes that issue as an out-of-bounds write that may allow full code execution on a device.
Why the same-day timing matters
For incident tracking, September 22, 2026 is the confirmed publication date for both lwIP-related advisories. But the advisories are not interchangeable: one concerns affected lwIP API versions, while the other concerns the MQTT Client Application.
If you are using this timeline for remediation planning, re-check the CISA pages for any revisions after the original publication date.
Sources / Learn more
Related reading
- How can lwIP users determine whether their MQTT Client Application version is vulnerable?; What should teams do to update affected lwIP MQTT Client Application deployments?; How does CVE-2026-87121 change the risk profile for devices using the lwIP MQTT Client Application?
- How can teams determine whether their SIMOVE Fleetmanager or SIPLANT version is affected by CVE-2026-67367?; What should Siemens SIMOVE Fleetmanager and SIPLANT users do after the September 22, 2026 CISA advisory?; What could the path traversal vulnerability allow an attacker to access?; Which SIMOVE Fleetmanager versions are listed as affected before the fixed releases?
- What should someone do if they used interest-free credit cards, a home equity loan, or a 401K withdrawal to pay for a SurgeU program and are now facing debt?
- How should organizations mitigate CVE-2026-34223 in Siemens Desigo CC family V6 and V7?; Which Siemens Desigo CC versions are affected by the client code execution vulnerability?; How can specially crafted graphics documents lead to client code execution in Desigo CC?; What changed after CISA’s September 22, 2026 advisory for Siemens Desigo CC family?

Leave a Reply