CPE
A critical buffer overflow vulnerability (CVE-2026-18397) in the Thales SConnect browser extension allows unauthenticated attackers to achieve remote code execution through malicious drive-by web pages.