AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0156 74.3 —
AFFECTED Product Versions Fixed lwIP 2.1.0 – —
TIMELINE May 18 Reserved by VulDB May 18 Published (CNA: VulDB) Aug 22 RESCORED — CVE-2026-8836 (lwIP). CVSS 9.3 → 8.9 (NVD).
Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N H H H 8.9 .0156 74.3 —
AFFECTED Product Versions Fixed lwIP 2.1.0 – —
TIMELINE May 18 Reserved by VulDB May 18 Published (CNA: VulDB) Aug 22 RESCORED — CVE-2026-8836 (lwIP). CVSS 9.3 → 8.9 (NVD).
A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow. The attack may be initiated remotely. The patch is named 0c957ec03054eb6c8205e9c9d1d05d90ada3898c. It is suggested to install a patch to address this issue. Two separate issue reports were submitted to the project. Their processing was merged as a duplicate.
| Date | Event | Detail |
|---|---|---|
| May 18, 2026 | Reserved | Reserved by VulDB |
| May 18, 2026 | Published | Published (CNA: VulDB) |
| August 22, 2026 | RESCORED | RESCORED — CVE-2026-8836 (lwIP). CVSS 9.3 → 8.9 (NVD). |
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
|---|---|---|---|---|
| n/a | lwIP | — | 2.1.0 | — |
Authoritative record: CVE-2026-8836 at cve.org
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-8836 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.