CVE-2026-19874 is a heap-based buffer overflow in Metal Gear Online 3 version 1.1.2.8's processing of Steam lobby metadata for removed players. The lobby-data parser uses the attacker-controlled kick_num value to determine how many kicked-player identifiers to copy, but does not enforce the maximum capacity of the corresponding 16-player buffer. Supplying an oversized count together with crafted kicked-player identifier fields causes out-of-bounds writes into adjacent heap memory, including Steamworks callback-handler structures containing callback arguments and function pointers. The resulting corruption can be used to hijack control flow and execute attacker-controlled code in the game process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Small 3-file repository containing a vulnerability write-up rather than standalone exploit code. The main content is assets/doc.md, which documents CVE-2026-19874 affecting METAL GEAR ONLINE 3 on Steam. The write-up describes a heap-based buffer overflow in parse_kicked_ids where attacker-controlled Steam lobby metadata key kick_num is not bounded to the 16-element kicked_ids array. By supplying excessive kicked_id_N values through Steam Matchmaking lobby data, a malicious host can overwrite adjacent fields in mgo_match_t, including Steam callback structures. The document explains that the attacker can then remotely trigger corrupted callbacks using ISteamMatchmaking::SetLobbyData or ISteamMatchmaking::SendLobbyChatMsg to hijack control flow and achieve remote code execution on clients who join the lobby. The repository includes reverse-engineered structure layouts, vulnerable pseudocode, target binary/version details, and a proof-of-concept sequence showing crafted lobby keys and callback overwrite offsets. There is no runnable exploit implementation in the repo, only documentation and pseudocode, so maturity is best classified as POC. The readme provides the CVE reference, disclosure timeline, and patch note link.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical remote code execution vulnerability in Metal Gear Online 3 lobby handling. A malicious lobby host can supply an oversized kick_num value, corrupt adjacent memory and Steamworks callback data, and potentially execute arbitrary code when a victim joins the lobby.
A critical remote code execution vulnerability in Metal Gear Online 3's multiplayer lobby system caused by a heap-based buffer overflow in the player-removal mechanism.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.