CVE-2026-18458

Summary

Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.3.0 before 7.3.1.6, from 6.1.2.21 before 6.1.*.

Affected Software

VendorProductVersion RangeStatus
RTIConnext Professional7.4.0 < 7.7.0.1affected
RTIConnext Professional7.3.0 < 7.3.1.6affected
RTIConnext Professional6.1.2.21 < 6.1.*affected

Weaknesses

  • CWE-125: CWE-125 Out-of-bounds Read
  • CWE-685: CWE-685 Function Call With Incorrect Number of Arguments
  • CWE-843: CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References