Skip to content
RCE Vulnerability in SConnect Affects Banks

RCE Vulnerability in SConnect Affects Banks

First seen 4 Oct 2026, 04:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 06:06 UTC
  • •SConnect has a critical RCE vulnerability (CVE-2026-18397) affecting over 1 million users.
  • •The flaw allows silent DLL execution via any site or iframe due to poor RSA-2048 validation.
  • •Version v2.16.0.0 is confirmed vulnerable, with a CVSS score of 9.4.

SConnect, an authentication middleware with over 1 million users, has a remote code execution (RCE) vulnerability (CVE-2026-18397) due to a flawed RSA-2048 token validation implementation. This flaw allows any site or iframe viewed by an user to silently download and execute a DLL, exploiting uninitialized memory validation bypasses. The vulnerable version is v2.16.0.0 of both the extension and native host. The vulnerability was published on October 1, 2026, with a CVSS score of 9.4, indicating a severity. While the exact number of affected banks is unclear, the potential impact could be significant given the architecture's risks. The vulnerability highlights the dangers of extension and native host implementations in authentication systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-01
CVE-2026-18397 published
A critical RCE vulnerability in SConnect was disclosed, affecting version v2.16.0.0.
amibeingpwned.com

More articles in this cluster (2)

Following this threat?

Track CVE-2026-18397 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of SConnect are affected?
Version v2.16.0.0 of SConnect is confirmed vulnerable.
Is there a patch available?
The articles do not mention if a patch has been released yet.
What is the potential impact of this vulnerability?
The vulnerability could allow attackers to execute malicious DLLs on users' systems, posing significant risks.