Real-Time Innovations, Inc. (RTI) maintains a specialized product line focused on data-distribution middleware and real-time communication frameworks, particularly the Connext DDS platform family, which addresses deterministic messaging and integration needs in embedded and aerospace-defense contexts. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and cluster persistently around memory-safety weakness classes, including classic buffer overflows, stack-based overflows, out-of-bounds reads and writes, and buffer over-reads that are characteristic of C/C++-based middleware operating in resource-constrained environments. The exposure spans multiple Connext product variants (Professional, Secure, and Micro editions), where the memory-handling patterns recur across versions and configurations. Defenders deploying RTI middleware in mission-critical or networked environments should prioritize patching and validate that embedded instances are kept current; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Real-Time Innovations, Inc. over time
Of all the CVEs published by Real-Time Innovations, Inc. as a CNA, 100.0% affect products that Real-Time Innovations, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Real-Time Innovations, Inc., 88.2% are self-published by Real-Time Innovations, Inc. as a CNA.
Signals from CVEs in this vendor scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3894CRITICAL Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 b | Jun 17, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-30803CRITICAL Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: from 4.0.0 before 4.3.0. | Jun 17, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-2467HIGH Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before | Jun 17, 2026 | 8.1 | 35 | NO | NO |
CVE-2026-30802HIGH Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: from 4.0.0 before 4.3.0, from 2.4.5 before 2.4.*. | Jun 17, 2026 | 8.2 | 33 | NO | NO |
CVE-2025-14543CRITICAL Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext | Apr 30, 2026 | 9.1 | 32 | NO | NO |
CVE-2025-1255CRITICAL Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.This issue affects Connext Professional: from 7.4.0 before 7.6. | Sep 23, 2025 | 9.1 | 32 | NO | NO |
CVE-2026-2674HIGH Out-of-bounds Write, Out-of-bounds Write, Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence Service) allows Overflow Buffer | Jun 17, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-30799HIGH Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing.This issue affects Connext Professional: from 7.4 | Jun 17, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-7300MEDIUM Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Filter Failure through Buffer Over | Jun 17, 2026 | 6.5 | 29 | NO | NO |
CVE-2026-4374CRITICAL Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service, Recording Service, Routing Service, Queueing Service, Obse | Apr 1, 2026 | 9.1 | 29 | NO | NO |
Signals from CVEs in this vendor scope (34 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Real-Time Innovations, Inc..
Media articles that mention a CVE ID that affects a product developed by Real-Time Innovations, Inc. — matched by CVE ID, not by vendor name.