OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-18397

CRITICAL · CVSS 9.4 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

This critical vulnerability allows unauthenticated remote code execution on affected systems by exploiting cryptographic weaknesses and memory management flaws in the SConnect native host component. Attackers can leverage an unrestricted messaging interface to send malicious input that bypasses security checks, potentially compromising the victim's machine. Organizations using this component should prioritize immediate remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-18397
Severity
CRITICAL
CVSS
9.4
EPSS
0.34%

Original NVD Description

This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.