CVE-2026-2394Medium· 6.5▾ SunlitBuffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 befo…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
6.3 → 6.5
Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0., from 5.3.0 before 5.3., from 5.2.0 before 5.2., from 4.3x before 5.1..
connext_professional >= 4.3.0, <= 5.2.3connext_professional >= 5.3.0, <= 5.3.1.45connext_professional >= 6.0.0, <= 6.0.1.40connext_professional >= 6.1.0, <= 6.1.2.27connext_professional >= 7.0.0, < 7.3.1.1connext_professional >= 7.4.0, < 7.7.0Upgrade past the affected range:
connext_professional 7.7.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-4582High· 7.1Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, Overread Buffers
CVE-2025-1254High· 7.4Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Buffers, Overread Buffers
CVE-2025-8410High· 7.4Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation
CVE-2026-3894Critical· 9.1Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers
CVE-2026-11389Medium· 6.8Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers
CVE-2026-18458Medium· 6.8Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers