CVE-2026-4374
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (multiple infrastructure services) allows Serialized Data External Linking, Data Serialization External Entities Blowup.
CVSS Score
0.0
EPSS Score
0.2%
EPSS Percentile
14th
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service, Recording Service, Routing Service, Queueing Service, Observability Collector) allows Serialized Data External Linking, Data Serialization External Entities Blowup.<p>This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.1.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*.</p>
| CWE | CWE-611 |
| Vendor | rti |
| Product | connext professional |
| Published | Apr 1, 2026 |
| Last Updated | Jun 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for rti connext professional
Be the first to know when new unknown vulnerabilities affecting rti connext professional are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
RTI / Connext Professional
7.4.0 < 7.7.0 7.1.0 < 7.3.1.1 6.1.0 < 6.1.2.34 6.0.0 < 6.0.* 5.3.0 < 5.3.*