CVE-2026-19874

Metal Gear Online 3
26/100
exploitation likelihood
CVSS9.1
EPSS0.7%
KEVNone
A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers using the lobby data key "kick_num" to determine the number of entries, and individual kicked player IDs supplied via keys in the format "kicked_id_%i". The function does not validate that "kick_num" falls within the expected bounds. The game design limits matches
EPSS 0.007 (probability of exploitation) · CVSS base 9.1 · 1 public PoC/exploit reference(s) available
Public PoC / Exploit1

Defensive review only — these references demonstrate exploitability.

References3