CVE-2026-8876

HIGH

Securly Chrome Extension < 3.0.7 - Hardcoded AES Passphrase Exposure

Title source: llm
STIX 2.1

Description

Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These keys decrypt crisis alert keyword data and intervention site data.

References (1)

Core 1

Scores

CVSS v3 7.3
EPSS 0.0018
EPSS Percentile 7.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-798
Status published
Products (2)
securly/securly 3.0.7
Securly/Securly Chrome Extension < 3.0.7
Published Jun 03, 2026
Tracked Since Jun 04, 2026