Junglewise Threat Intelligence

CVE-2026-8849: RTI Connext Professional use-after-free in Security Plugins

CVE-2026-8849 · Severity: info · Published 2026-09-22

Technologies: Rti Connext Professional. Vendors: Rti.

Executive brief

RTI Connext Professional is middleware software that enables real-time communication between distributed systems in industrial and enterprise environments. A use-after-free vulnerability in its Security Plugins component could allow an attacker to manipulate files or cause system instability in applications relying on this software.

Technical details

A use-after-free vulnerability exists in RTI Connext Professional versions 7.6.0 through 7.7.0.0 within the Security Plugins component. The flaw allows file manipulation through memory reuse after the vulnerable object is freed. The vulnerability is rated informational severity and affects the security plugin initialization or file handling mechanisms.

Affected products

  • RTI Connext Professional 7.6.0 to 7.7.0.0

Timeline

  • 2026-09-22: disclosed

References

Related threats