CVE-2026-18459: Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality.
Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1., from 6.0.0 before 6.0., from 5.3.0 before 5.3., from 5.2.0 before 5.2., from 4.1x before 5.1..
Affected Software
Event History
Frequently Asked Questions
How can I determine whether an installation is within the affected scope?
Check the installed Connext Professional Core Libraries version against the listed ranges: 7.4.0 through versions before 7.7.0.1, or 7.0.0 through versions before 7.3.1.6. Earlier affected branches begin at 6.1.0, 6.0.0, 5.3.0, 5.2.0, and 4.1x, with the stated upper branch limits.
Which fixed versions are explicitly identified for the newer release branches?
The explicitly identified remediation versions are 7.7.0.1 for the 7.4.x branch and 7.3.1.6 for the 7.0.x branch. For the older branches, the available information specifies wildcard branch limits rather than a discrete fixed patch version.