Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-18461: RTI Connext Professional core libraries allow format string injection

CVE-2026-18461 · published 18 days ago
Summary

The core libraries in RTI Connext Professional (versions before 7.7.0.1 and 7.3.1.6) can be tricked into processing attacker‑controlled text as a format string. This could let an attacker read or modify memory, potentially leading to crashes or unauthorized code execution. Update to the latest released version of Connext Professional to eliminate the risk.

What to do
  • Update rti connext professional to version 7.7.0.1 or later.
Affected software
VendorProductAffected versions
rti connext professional < 7.7.0.1
Original advisory text
Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection.
Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. This issue affects Connext Professional: from 7.5.0 before 7.7.0.1, from 7.3.0.10 before 7.3.1.6.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-134Use of Externally-Controlled Format String
Timeline
Published22 Sep 2026
Updated7 Oct 2026
First seen22 Sep 2026
Sources
CVE-2026-18461 · MITRE
Track software like this
Free during beta