๐Ÿ” CVE Alert

CVE-2026-4374

UNKNOWN 0.0

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (multiple infrastructure services) allows Serialized Data External Linking, Data Serialization External Entities Blowup.

CVSS Score
0.0
EPSS Score
0.2%
EPSS Percentile
14th

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service, Recording Service, Routing Service, Queueing Service, Observability Collector) allows Serialized Data External Linking, Data Serialization External Entities Blowup.<p>This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.1.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*.</p>

CWE CWE-611
Vendor rti
Product connext professional
Published Apr 1, 2026
Last Updated Jun 25, 2026
Stay Ahead of the Next One

Get instant alerts for rti connext professional

Be the first to know when new unknown vulnerabilities affecting rti connext professional are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

RTI / Connext Professional
7.4.0 < 7.7.0 7.1.0 < 7.3.1.1 6.1.0 < 6.1.2.34 6.0.0 < 6.0.* 5.3.0 < 5.3.*

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
rti.com: https://www.rti.com/vulnerabilities/#cve-2026-4374