Junglewise Threat Intelligence

CVE-2026-11389: RTI Connext Professional out-of-bounds read in core libraries

CVE-2026-11389 · Severity: info · Published 2026-09-22

Technologies: Rti Connext Professional. Vendors: Rti.

Executive brief

RTI Connext Professional is a middleware platform for distributed real-time systems communication. This vulnerability allows an attacker to read beyond allocated buffer boundaries in the core libraries, potentially exposing sensitive data or causing system instability. The issue affects multiple versions and requires network access to trigger.

Technical details

An out-of-bounds read combined with type confusion and incorrect function call arguments exists in RTI Connext Professional's core libraries. The vulnerability allows an attacker with network access to overread buffers, potentially disclosing sensitive information. Patches are available for affected versions 7.4.0–7.7.0.1 and 7.3.0–7.3.1.6.

Affected products

  • RTI Connext Professional 7.3.0 before 7.3.1.6, 7.4.0 before 7.7.0.1

Timeline

  • 2026-09-22: disclosed

References

Related threats