CVE-2025-29366

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

In mupen64plus v2.6.0 there is an array overflow vulnerability in the write_rdram_regs and write_rdram_regs functions, which enables executing arbitrary commands on the host machine.

Published 2025-08-22. Last modified 2026-06-17.