CVE-2026-18459
Received Received - Intake

Incorrect Calculation in RTI Connext Professional

Vulnerability report for CVE-2026-18459, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: RTI

Description

Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.0 before 5.2.*, from 4.1x before 5.1.*.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
rti connext_professional From 7.4.0 (inc) to 7.7.0.1 (exc)
rti connext_professional From 7.0.0 (inc) to 7.3.1.6 (exc)
rti connext_professional From 6.1.0 (inc) to 6.1.* (exc)
rti connext_professional From 6.0.0 (inc) to 6.0.* (exc)
rti connext_professional From 5.3.0 (inc) to 5.3.* (exc)
rti connext_professional From 5.2.0 (inc) to 5.2.* (exc)
rti connext_professional From 4.1x (inc) to 5.1.* (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-682 The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Incorrect Calculation issue in RTI Connext Professional (Core Libraries) that allows abuse of existing functionality. It affects multiple versions of the software, specifically those before 7.7.0.1, 7.3.1.6, 6.1.*, 6.0.*, 5.3.*, 5.2.*, and 4.1x before 5.1.*.

Impact Analysis

The vulnerability could allow attackers to manipulate calculations or exploit existing features in RTI Connext Professional, potentially leading to unauthorized access, data corruption, or system disruptions. The high CVSS score of 8.7 indicates a significant risk.

Compliance Impact

The vulnerability's impact on compliance with standards like GDPR or HIPAA is not explicitly described in the provided CVE data. The issue involves incorrect calculation leading to potential abuse of functionality, which could theoretically affect data integrity or security controls relevant to compliance.

Mitigation Strategies

Update RTI Connext Professional to a patched version: 7.7.0.1 or later for 7.4.0+, 7.3.1.6 or later for 7.0.0+, or the latest supported version for older releases.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18459. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart