Vulnerability Description
Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These keys decrypt crisis alert keyword data and intervention site data.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Securly | Securly | 3.0.7 |
Related Weaknesses (CWE)
References
- https://kb.cert.org/vuls/id/595768Third Party Advisory
FAQ
What is CVE-2026-8876?
CVE-2026-8876 is a vulnerability with a CVSS score of 7.3 (HIGH). Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These keys decrypt crisis alert keyword data and intervention site data.
How severe is CVE-2026-8876?
CVE-2026-8876 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-8876?
Check the references section above for vendor advisories and patch information. Affected products include: Securly Securly.