Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-10-05 · updated: 2026-10-05 · tags: [cve] · confidence: medium · severity: critical · affected_sectors: [global] · au_impact: false

Researchers at Bay Area Labs disclosed (report shared with Dark Reading ahead of publication) a critical vulnerability — CVE-2026-18397, published 1 October with a CVSS 4.0 score of 9.4 — in SConnect, the Thales-owned browser-extension-plus-native-host middleware used for hardware-token (3SKey) authentication to the SWIFT banking network, national government identity systems including Qatar's Tawtheeq and the Swedish Tax Agency (Skatteverket), and various banking and insurance portals, with more than 1 million Chrome Web Store users.

Attribute Detail
CVE CVE-2026-18397
CVSS 9.4 (CVSS 4.0)
Vendor / product Thales / SConnect native host component
Reported 2026-10-05