CVE-2026-95509: Qt For Mcus

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bounds reading.

Affected products

  • Qt Qt For Mcus: from 2.6.0, before 2.11.3 (fixed in 2.11.3); from 2.12.0, before 2.12.3 (fixed in 2.12.3)

Published 2026-09-29. Last modified 2026-09-30.