CVE-2026-18461: Rti Connext Professional
Critical severity, CVSS 9.2. EPSS: 0.2% chance of exploitation in the next 30 days.
Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. This issue affects Connext Professional: from 7.5.0 before 7.7.0.1, from 7.3.0.10 before 7.3.1.6.
Affected products
- Rti Connext Professional: from 7.5.0, before 7.7.0.1 (fixed in 7.7.0.1); from 7.3.0.10, before 7.3.1.6 (fixed in 7.3.1.6)
Published 2026-09-22. Last modified 2026-09-22.