← Vulnerability feed

Vulnerability record · CVE-2026-2467 · published 17 June 2026

CVE-2026-2467: Rti connext professional heap-based buffer overflow vulnerability

Rti · Connext Professional

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 5.0.0 before 5.1.*.

9.2 CVSS 4.0 Critical EPSS 0.19% · top 92.4% CWE-122 · Heap-based buffer overflow
9.2CVSS 4.0 base score
0.19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
22 Sep 2026Last modified by NVD

Description

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 5.0.0 before 5.1.*.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.rti.com/vulnerabilities/#cve-2026-2467 MitigationVendor Advisory

Track CVE-2026-2467 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-38435Rti connext professional vulnerabilityRTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 not correctly calculate the size when allocating the buffer, which may res…EPSS 1.4%9.2CVE-2026-3894Rti connext professional out-of-bounds read vulnerabilityOut-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from …EPSS 0.33%9.1CVE-2024-52057Rti connext professional sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RTI Connext Professional (Queuing Service) allo…EPSS 0.41%8.8CVE-2026-7300Rti connext professional classic buffer overflow vulnerabilityBuffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Fil…EPSS 0.42%8.8CVE-2025-14543Rti connext professional xml external entity (xxe) vulnerabilityImproper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Link…EPSS 0.21%8.8CVE-2026-4374Rti connext professional xml external entity (xxe) vulnerabilityImproper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Recording Service,Routing Service,Queueing Service,C…EPSS 0.39%8.8CVE-2021-38487Rti connext dds micro vulnerabilityRTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted pa…EPSS 3.4%8.6CVE-2024-52058Rti connext professional os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in RTI Connext Professional (System Designer…EPSS 0.63%

Source: NIST National Vulnerability Database (record CVE-2026-2467), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.