amibeingpwned.com RCE Vulnerability in SConnect Affects Banks
Article Content
- •SConnect has a critical RCE vulnerability (CVE-2026-18397) affecting over 1 million users.
- •The flaw allows silent DLL execution via any site or iframe due to poor RSA-2048 validation.
- •Version v2.16.0.0 is confirmed vulnerable, with a CVSS score of 9.4.
SConnect, an authentication middleware with over 1 million users, has a remote code execution (RCE) vulnerability (CVE-2026-18397) due to a flawed RSA-2048 token validation implementation. This flaw allows any site or iframe viewed by an user to silently download and execute a DLL, exploiting uninitialized memory validation bypasses. The vulnerable version is v2.16.0.0 of both the extension and native host. The vulnerability was published on October 1, 2026, with a CVSS score of 9.4, indicating a severity. While the exact number of affected banks is unclear, the potential impact could be significant given the architecture's risks. The vulnerability highlights the dangers of extension and native host implementations in authentication systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-18397 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of SConnect are affected?
Is there a patch available?
What is the potential impact of this vulnerability?
Continue Reading
Critical Vulnerability Found in Thales SConnect Allows Remote Code Execution A critical vulnerability, CVE-2026-18397, has been identified in Thales SConnect, enabling unauthenticated remote code execution (RCE) on affected systems. The flaw arises from cryptographic weaknesses and memory management issues, allowing attackers to exploit an unrestricted messaging interface between a web page…
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…