ThreatsIndustrial & OTBreakingCritical lwIP Embedded TCP/IP Stack Double Free Flaw Exposes Industrial Controllers to Remote Hijacking CVE-2026-91018CISA and lwIP maintainers warn of high-severity flaw CVE-2026-91018 in the lwIP TCP/IP stack allowing unauthenticated remote memory corruption across IoT and PLCs.CST Newsroom·23 Sep 2026, 16:00 IST·16 min read