Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

Metal Gear Online 3 vulnerability allowed remote code execution

A critical heap-based buffer overflow (CVE-2026-19874, CVSS 9.1) in Metal Gear Online 3's multiplayer lobby system allowed malicious lobby hosts to achieve remote code execution by sending oversized values to the player-removal mechanism, triggering out-of-bounds writes. The vulnerability, which required no user interaction beyond joining a compromised lobby, affected version 1.1.2.8 and was fixed in version 1.1.2.9.
Read Full Article →

Vulnerability Management Metal Gear Online 3 vulnerability allowed remote code execution August 24, 2026 Share By SC Staff As reported by Cyber Insider, a critical vulnerability in Konami's Metal Gear Online 3 allowed malicious actors to execute arbitrary code on players' computers. The flaw, identified as CVE-2026-19874, was present in the multiplayer lobby system and has since been patched by Konami. The vulnerability, discovered by researcher Alice Cecchetto and detailed by CERT/CC, stemmed from a heap-based buffer overflow in the game's player-removal mechanism. Malicious lobby hosts could exploit this by sending oversized values for the kick_num field, causing out-of-bounds writes that could corrupt adjacent memory structures. This corruption could redirect program execution, allowing attackers to run their own code, potentially leveraging read-write-execute memory regions protected by Denuvo. Exploitation was automatic upon joining an attacker-controlled lobby, requiring no user interaction. The issue affected version 1.1.2.8 and was fixed in version 1.1.2.9, released on August 4, 2026. Konami has not issued a specific advisory, but the update prevents older clients from accessing online services. Players are advised to ensure their game is updated to the latest version before engaging in online multiplayer to mitigate the risk. Source: Cyber Insider SC Staff Related Vulnerability Management WordPress plugin vulnerabilities allow admin account takeover SC Staff August 24, 2026 The vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to bypass authentication. Vulnerability Management CISA adds Zimbra Collaboration Suite bug to exploited vulnerabilities list Steve Zurier August 24, 2026 Experts warn that it’s the fifth time Zimbra made the KEV this year. Vulnerability Management TrueConf flaws enabling attacks on meeting participants added to KEV catalog Laura French August 21, 2026 The flaws have been used by the Head Mare APT hacktivist group to spread PhantomCore malware. Related Events Cybercast State of Vulnerability Management Thu Sep 10 Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article