type: cve · created: 2026-10-05 · updated: 2026-10-05 · tags: [cve] · confidence: medium · severity: critical · affected_sectors: [global] · au_impact: false
Researchers at Bay Area Labs disclosed (report shared with Dark Reading ahead of publication) a critical vulnerability — CVE-2026-18397, published 1 October with a CVSS 4.0 score of 9.4 — in SConnect, the Thales-owned browser-extension-plus-native-host middleware used for hardware-token (3SKey) authentication to the SWIFT banking network, national government identity systems including Qatar's Tawtheeq and the Swedish Tax Agency (Skatteverket), and various banking and insurance portals, with more than 1 million Chrome Web Store users.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-18397 |
| CVSS | 9.4 (CVSS 4.0) |
| Vendor / product | Thales / SConnect native host component |
| Reported | 2026-10-05 |