OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-18461

CRITICAL · CVSS 9.2 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A critical vulnerability exists in RTI Connext Professional Core Libraries, where an externally-controlled format string can lead to format string injection. This flaw affects versions from 7.5.0 to before 7.7.0.1 and from 7.3.0.10 to before 7.3.1.6, potentially allowing attackers to execute arbitrary code or manipulate application behavior. Organizations utilizing these specific versions should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-18461
Severity
CRITICAL
CVSS
9.2
EPSS
0.21%

Original NVD Description

Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. This issue affects Connext Professional: from 7.5.0 before 7.7.0.1, from 7.3.0.10 before 7.3.1.6.