CVE-2026-19874Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers using the lobby data key "kick_num" to determine the number of entries, and individual kicked player IDs supplied via keys in the format "kicked_id_%i". The function does not validate that "kick_num" falls within the expected bounds. The game design limits matches to a maximum of 16 players, and the corresponding buffer for storing kicked player IDs is sized accordingly. If "kick_num" exceeds this limit, the function continues writing the provided player IDs past the end of the intended buffer and into adjacent memory regions. These adjacent regions contain Steam callback handler structures responsible for processing lobby data updates, lobby messages, and other related events. By supplying an oversized "kick_num" value and appropriate "kicked_id_%i" fields, an attacker can overwrite fields within the callback handler structures, including function pointers and callback argument values. Successful exploitation may enable control-flow hijacking, potentially allowing arbitrary code execution within the game process.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-08-25); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-08-24: 2Mentions · 2026-08-25: 4Mentions · 2026-08-27: 1Patch / Workaround · 2026-08-24: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-24: 2Technical Details · 2026-08-25: 3Technical Details · 2026-08-27: 108-2408-2508-27
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
General
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-242
Disclosure1Patch1
2026-08-254
Disclosure2General1Patch1
2026-08-271
Disclosure1
Full discourse7 posts
  • kokumօtօ@__kokumoto
    Disclosure

    コナミのMetal Gear Online 3(ゲーム)に遠隔コード実行の脆弱性。CVE-2026-19874はCVSSスコア9.1で、ヒープベースのバッファオーバーフロー。悪意あるホストが接続クライアントを乗っ取れる。ホストがマッチを抜けるとサーバ権限は他のユーザに移るので、それからも刺さる。 https://securityonline.info/metal-gear-online-3-rce-cve-2026-19874/

    Post summary

    The post discloses a heap‑based buffer overflow causing RCE in Metal Gear Online 3 (CVE-2026-19874) with a CVSS score of 9.1, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    04061995
    7.8K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Patch

    🎮 Un simple salon #Steam pouvait suffire à faire exécuter du code arbitraire sur votre #PC dans Metal Gear Online 3. 👀 The Phantom Pain contenait une vulnérabilité importante… #Gaming #MetalGear 👉 Découvrez la mise à jour corrective : https://www.it-connect.fr/metal-gear-online-3-faille-rce-cve-2026-19874/

    Post summary

    The post highlights CVE‑2026‑19874 in Metal Gear Online 3, noting it allows arbitrary code execution via a Steam lobby, and directs readers to a corrective update.

    01050823
    11.7K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Metal Gear Online 3 RCE vulnerability CVE-2026-19874 fixed. Update the game to prevent attackers from executing remote code on your system. #MetalGearOnline3 #CyberSecurity #Vulnerability #CVE202619874 http://securityonline.info/metal-gear-online-3-rce-cve-2026-19874/

    Post summary

    CVE-2026-19874, a remote code execution flaw in Metal Gear Online 3, has been fixed; users are advised to update the game to mitigate the risk.

    00010445
    12.9K followersView on X
  • Cybersecurity News DE@cybsecuritynews
    Disclosure

    #schwachstellen CVE-2026-19874 in Metal Gear Online 3: Kritische Heap-Überlauf-Schwachstelle kann Codeausführung ermöglichen #cve202619874 #konami #metalgearonline3 #steam https://cybersecurity-news.de/cve-2026-19874-metal-gear-online-3-heap-overflow

    Post summary

    The tweet announces CVE‑2026‑19874 as a critical heap‑overflow vulnerability in Metal Gear Online 3 that could enable code execution, without providing PoC, exploit, patch, or active exploitation details.

    0000066
    10 followersView on X
  • リアルタイムニュース.com@RTM_commmmm
    Disclosure

    「メタルギアオンライン」で、ロビーに参加しただけでPCを乗っ取られる脆弱性(CVE-2026-19874)が見つかった。 メタルギアオンラインに致命的欠陥、ロビー参加だけでPC乗っ取り ▼ 詳しくはこちら https://reaitimenews.com/entry/metal-gear-online-3-rce-vulnerability #メタルギアオンライン #脆弱性 #セキュリティ

    Post summary

    A new vulnerability (CVE-2026-19874) was identified in Metal Gear Online that allows an attacker to take over a PC by simply joining the lobby, but no PoC, exploit, or patch details are provided.

    00000419
    2.1K followersView on X
  • thibault@akril
    General

    [IT-Connect] - Metal Gear Online 3 : rejoindre un salon Steam suffisait à faire exécuter du code sur votre PC - https://www.it-connect.fr/metal-gear-online-3-faille-rce-cve-2026-19874/ 👌😁

    Post summary

    The article reports that CVE‑2026‑19874 in Metal Gear Online 3 allows remote code execution simply by joining a Steam room; no exploit details, tool, patch or active exploitation evidence are provided.

    0000098
    686 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-19874 Heap Buffer Overflow in Metal Gear Online 3 Enables Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-19874

    Post summary

    CVE‑2026‑19874 is a heap buffer overflow vulnerability in Metal Gear Online 3 that could lead to code execution; the brief notice gives technical details but includes no PoC, exploit code, or mitigation information.

    00000137
    4.1K followersView on X

Explore more