CVE-2026-4374CRITICAL 9.1EPSS p30.9%

CVE-2026-4374CVE-2026-4374

rti / connext_professional

Description

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Recording Service,Routing Service,Queueing Service,Cloud Discovery Service,Observability Collector) allows Serialized Data External Linking, Data Serialization External Entities Blowup. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*.

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS0.39% probability of exploitation · percentile 30.9% · 2026-10-06T12:00:23Z
Published2026-04-01
Last modified2026-09-22

Underlying weaknesses· 1

CWE-611

References

  1. https://www.rti.com/vulnerabilities/#cve-2026-4374

1

TypeTargetConfidenceTier
WeaknessImproper Restriction of XML External Entity Referencecwe-6110%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-14543
CVE
CVE-2025-4993
CVE
CVE-2026-8045
CVE
CVE-2025-1255
CVE
NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability
CVE
CVE-2024-5625
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.