Thales GroupCVE-2026-18397
Thales Group SConnect: remote code execution
Critical9.4CVE-2026-18397 · Published Oct 1, 2026 · updated Oct 2, 2026
This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SConnect Product | < 2.16.1.0 | 2.16.1.0 |