Junglewise Threat Intelligence

CVE-2026-18461: RTI Connext Professional format string injection in Core Libraries

CVE-2026-18461 · Severity: info · Published 2026-09-22

Technologies: Rti Connext Professional. Vendors: Rti.

Executive brief

RTI Connext Professional is middleware that enables real-time data sharing between distributed applications in automotive, industrial, and financial systems. A format string vulnerability in its Core Libraries could allow an attacker to read memory, crash the application, or potentially execute code if they can inject malicious format strings into the system. Organizations using affected versions should apply the security patches released by RTI.

Technical details

The Core Libraries component in RTI Connext Professional contains a use of externally-controlled format string vulnerability that enables format string injection attacks. An attacker with network access or local access to the system can inject format strings to read or write memory, leading to information disclosure or denial of service. RTI has released patches for affected versions (7.7.0.1 and later for the 7.5.x branch, 7.3.1.6 and later for the 7.3.x branch).

Affected products

  • RTI Connext Professional 7.5.0 to 7.7.0.0, 7.3.0.10 to 7.3.1.5

Timeline

  • 2026-09-22: disclosed

References

Related threats