PT-2026-96891 · Unknown · Rti Connext Professional
CVE-2026-18461
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Connext Professional versions 7.5.0 through 7.7.0
Connext Professional versions 7.3.0.10 through 7.3.1.5
Description
Use of an externally-controlled format string in the Core Libraries allows for Format String Injection. This occurs when an application uses a format string provided by an external source, potentially allowing an attacker to read or write to memory.
Recommendations
Update Connext Professional versions 7.5.0 through 7.7.0 to version 7.7.0.1.
Update Connext Professional versions 7.3.0.10 through 7.3.1.5 to version 7.3.1.6.
Fix
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rti Connext Professional