Junglewise Threat Intelligence

CVE-2026-2467: RTI Connext Professional heap overflow in Core Libraries

CVE-2026-2467 · Severity: info · CVSS 9.2 · Published 2026-06-17

Vendors: Rti.

Executive brief

RTI Connext Professional is a connectivity framework used for data exchange in distributed systems like industrial automation and aerospace. A memory management flaw in its core libraries could allow an attacker to disrupt system operations or cause a service outage. This could lead to a loss of availability for critical real-time communications and potentially impact system integrity.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in the Core Libraries of RTI Connext Professional. The flaw is triggered by improper handling of 'Overflow Variables and Tags' during data processing. An unauthenticated attacker can exploit this over the network without user interaction to cause a crash (denial of service) or potentially achieve limited unauthorized modification of data. The vulnerability affects multiple long-term support (LTS) versions, and RTI has released patches for active versions including 7.3.1.3 and 7.7.0.

Affected products

  • RTI Connext Professional (Core Libraries) 7.4.0 before 7.7.0, 7.0.0 before 7.3.1.3, 6.1.0 before 6.1.*, 6.0.0 before 6.0.*, 5.3.0 before 5.3.*, 5.0.0 before 5.2.*

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats