By vendor

Rti vulnerabilities

Known CVEs affecting Rti products, prioritized by severity, with SEC.co remediation and detection guidance.

5 published vulnerabilities

  • CVE-2026-30802HIGH 8.2

    RTI Connext Micro, a real-time middleware platform used in distributed systems, contains a flaw that allows an attacker to read beyond the intended boundaries of a memory buffer. An unauthenticated attacker on the network can exploit this without user interaction to leak sensitive data from the application's memory or crash the service. The vulnerability affects Connext Micro versions from 4.0.0 up to (but not including) 4.3.0, and from 2.4.5 up to (but not including) 2.4.x where a patched version exists.

  • CVE-2026-2467HIGH 8.1

    A heap-based buffer overflow vulnerability exists in RTI Connext Professional's core libraries that allows authenticated users to overflow variables and tags in memory. An attacker with valid credentials can trigger this flaw to corrupt data or crash the application, but cannot directly read sensitive information. The vulnerability affects multiple versions of Connext Professional spanning several major releases.

  • CVE-2026-2674HIGH 8.1

    RTI Connext Professional contains an out-of-bounds write vulnerability affecting three key components: the Queueing Service, Core Libraries, and Persistence Service. An authenticated attacker can send a crafted message over the network to trigger a buffer overflow, potentially corrupting memory and causing a denial of service or allowing code execution. The vulnerability affects multiple version branches and requires network access plus valid credentials to exploit.

  • CVE-2026-30799HIGH 8.1

    RTI Connext Professional's security plugin layer is missing proper authentication checks on critical functions, allowing an authenticated user to impersonate other identities within the system. While this requires an attacker to already have legitimate access credentials, the impact is severe: unauthorized changes to system configuration or data could occur without detection. The vulnerability spans multiple product versions from 5.3.0 through 7.7.0.

  • CVE-2026-2675MEDIUM 6.5

    RTI Connext Professional's security plugins contain a missing authentication check on a critical function, allowing an authenticated user to impersonate the source of data messages. This undermines the integrity of distributed data flows without requiring elevated privileges or user interaction. An attacker with valid credentials to the Connext system could inject falsified data that appears to originate from legitimate sources, potentially disrupting dependent applications that rely on data provenance.