PULSE
LIVE95signals / 24h
FEED
ransomglobal secret group reclama a Louisiana Coalition Against | Domestic Violence · US · Otherransomcrpxo reclama a ProSmile Family Dental Care · US · Healthcareransomcrpxo reclama a Qube Aviation Catering · US · Transportationransomcrpxo reclama a Performance Data Solutions · US · Professional Servicesransomcrpxo reclama a Host & Protect (RedBlink) · US · Technologyransomcrpxo reclama a RnnR Cloud · US · Technologyransomcrpxo reclama a CodeConductor.ai · US · Technologyransomcrpxo reclama a Prei Capital · US · Financial Servicesransomcrpxo reclama a FLP Law Group LLP · US · Professional Servicesransomcrpxo reclama a Summit Hill Insurance · US · Financial Servicesransomcrpxo reclama a MRO Aerospace · US · Manufacturingransomincransom reclama a takethehop.com · US · Hospitalityransomglobal secret group reclama a Park Manufacturing Corp. · US · Manufacturingransomexfilsquad reclama a Wesco International · US · Manufacturingransomglobal secret group reclama a Louisiana Coalition Against | Domestic Violence · US · Otherransomcrpxo reclama a ProSmile Family Dental Care · US · Healthcareransomcrpxo reclama a Qube Aviation Catering · US · Transportationransomcrpxo reclama a Performance Data Solutions · US · Professional Servicesransomcrpxo reclama a Host & Protect (RedBlink) · US · Technologyransomcrpxo reclama a RnnR Cloud · US · Technologyransomcrpxo reclama a CodeConductor.ai · US · Technologyransomcrpxo reclama a Prei Capital · US · Financial Servicesransomcrpxo reclama a FLP Law Group LLP · US · Professional Servicesransomcrpxo reclama a Summit Hill Insurance · US · Financial Servicesransomcrpxo reclama a MRO Aerospace · US · Manufacturingransomincransom reclama a takethehop.com · US · Hospitalityransomglobal secret group reclama a Park Manufacturing Corp. · US · Manufacturingransomexfilsquad reclama a Wesco International · US · Manufacturing
← All CVEs
CVE WatchJul 22, 2026

CVE-2026-8874

Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTT

CVSS

7.1

High

EPSS

0.1%

p4

KEV

Exploit Today

1

0-100

Published: Jun 3, 2026 · Last modified: Jul 22, 2026 · CWE-319

EPSS · 30d
0.1%EPSS · 30 days0.1%
2026-06-302026-07-25
Technical description

Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via the Fetch API. Other endpoints in the same extension correctly fetch IWF and CIPA data over HTTPS, demonstrating an inconsistent implementation of TLS.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-31824.3 MED
19.9%
6Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.5d
CVE-2026-472558.2 HIG
7.6%
2AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership checks for raw storage SQL; blocking direct storage metadata access through raw SQL; fail-closed outbound worker secret handling; SMTP envelope/header control-character validation before command construction; and TLS certificate verification as the default for MailSender with an explicit opt-out for local development. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 are patched.4d
CVE-2026-480226.5 MED
2.3%
1@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization before following a cross-origin redirect, but the origin check compares hostnames only and ignores scheme and port, so credentials are forwarded intact across same-host port changes and HTTPS-to-HTTP downgrades, allowing a co-tenant on an adjacent port or a network-position attacker capable of forging a redirect to capture bearer tokens, session cookies, and proxy credentials and impersonate the victim against the upstream service. This issue is fixed in version 18.1.2.4d
CVE-2026-48978
11.5%
3oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1.3d
CVE-2026-343465.5 MED
10.4%
3Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.5d
CVE-2026-536244.8 MED
7.6%
2Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of c.Scheme(). This issue is fixed in version 3.4.0.11d