Unauthenticated RCE in Thales SConnect native host
CVE-2026-18397 is a critical unauthenticated remote code execution flaw in the Thales SConnect native host, which connects web pages to local smart-card and token functions. An attacker-controlled web page can abuse an unrestricted messaging interface; improper cryptographic signature verification combined with length-parameter handling errors, unchecked return values, and use of uninitialized memory lets malicious input bypass security checks and run code on the victim machine. The victim must visit that page, no prior privileges are required, and success gives the attacker high impact on confidentiality, integrity, and availability of the host and connected systems. People and organizations with the SConnect native host installed, typically for digital-signature, e-banking, or e-government use, are affected; affected version ranges are not stated in the supplied data. No public proof of concept is known and the CVE is not in CISA KEV, so exploitation is not known to be occurring in the wild.
What to do: Install the fixed SConnect native-host build from the Thales PSIRT advisory as soon as it is published; no fixed version is identified in the data provided here. Until then, remove or disable the SConnect native host and its browser integration on machines that do not need smart-card or token access, and avoid opening untrusted web pages where it remains installed. Confirm whether the host is present by reviewing installed native-messaging hosts and related browser extensions.
| Thales SConnect native host | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.
No ingested article mentions this CVE yet.