CVE-2026-14757: Radare RADARE2

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file libr/core/cmd_anal.inc. This manipulation causes integer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. It is suggested to install a patch to address this issue.

Affected products

  • Radare RADARE2: from 6.1.0, before 6.1.8 (fixed in 6.1.8)

Published 2026-07-05. Last modified 2026-07-07.