Critical RCE Vulnerability in Metal Gear Online 3 Exploited

Critical RCE Vulnerability in Metal Gear Online 3 Exploited

First seen 24 Aug 2026, 22:52 UTC Kb.CertScmagazineScworldwww.cve.org 60.8

Article Content

Browse articles
ThreatCluster

A critical vulnerability (CVE-2026-19874) in Konami's Metal Gear Online 3 allows attackers to execute arbitrary code on players' machines via a heap-based buffer overflow in the multiplayer lobby system. This flaw, discovered by researcher Alice Cecchetto, enables malicious lobby hosts to exploit the kick_num field, leading to out-of-bounds writes that corrupt memory structures. The vulnerability affects version 1.1.2.8 of the game and was patched in version 1.1.2.9 released on August 4, 2026. Exploitation occurs automatically upon joining an attacker-controlled lobby, requiring no user interaction. Players are advised to update to the latest version to mitigate risks. As of now, Konami has not issued a specific advisory regarding this vulnerability.

Key Points: • CVE-2026-19874 allows remote code execution in Metal Gear Online 3. • The vulnerability is triggered by oversized kick_num values in lobby metadata. • Players must update to version 1.1.2.9 to protect against this exploit.

Timeline

2026-08-04
Patch released for Metal Gear Online 3
Konami released version 1.1.2.9 to fix the critical vulnerability CVE-2026-19874, preventing exploitation.
Scmagazine
2026-08-24
CVE-2026-19874 published
The vulnerability was officially published, detailing the remote code execution risk in Metal Gear Online 3.
Kb.Cert