Skip to content
CVE-2026-18397: Thales SConnect: This vulnerability enables unauthenticated remote ...

CVE-2026-18397: Thales SConnect: This vulnerability enables unauthenticated remote ...

Rapid7 • October 2, 2026

This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component.

The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.

CVSS 4.0 Base Score: 9.4 (CRITICAL)

CVSS 4.0 Vector: ( CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X )

Prioritise with Active Threat Intelligence

With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.

Extracted Entities

Attack Types (1)

Vulnerabilities (1)