Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-18461: RTI Connext Professional core libraries allow format string injection
CVE-2026-18461 · published 18 days ago
Summary
The core libraries in RTI Connext Professional (versions before 7.7.0.1 and 7.3.1.6) can be tricked into processing attacker‑controlled text as a format string. This could let an attacker read or modify memory, potentially leading to crashes or unauthorized code execution. Update to the latest released version of Connext Professional to eliminate the risk.
What to do
- Update rti connext professional to version 7.7.0.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| rti | connext professional | < 7.7.0.1 |
Original advisory text
Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection.
Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. This issue affects Connext Professional: from 7.5.0 before 7.7.0.1, from 7.3.0.10 before 7.3.1.6.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.2
Critical
Type
CWE-134Use of Externally-Controlled Format String
Timeline
Published22 Sep 2026
Updated7 Oct 2026
First seen22 Sep 2026
Track software like this
Free during beta