CVE-2026-18397
published 2026-10-01CVE-2026-18397: This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory…
PriorityP260critical9.4CVSS 4.0
AVNACLATNPRNUIPVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.34%
24.8th percentile
This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component.
The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| thales | sconnect | < 2.16.1.0 | 2.16.1.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native
ghsa_unreviewed·2026-10-02
CVE-2026-18397 [CRITICAL] CWE-130 This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native
This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component.
The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.
VulDB
Thales SConnect prior 2.16.1.0 Native Host privileges management
vuldb·2026-10-02·CVSS 9.4
CVE-2026-18397 [CRITICAL] Thales SConnect prior 2.16.1.0 Native Host privileges management
A vulnerability, which was classified as very critical, was found in Thales SConnect. This issue affects some unknown processing of the component Native Host. Executing a manipulation can lead to improper privilege management.
The identification of this vulnerability is CVE-2026-18397. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-10-01
Published