VU#595768: Securly Chrome Extension contains multiple weak encryption and access control vulnerabilities

2026-06-03T20:52:10Z5875a3a49cc1eb6a1330651de2b544d30c74659c1b69cedd1d995bb4fab452f7
caesar-cipherchrome-extensioncodemirrorcredential-theftdevice-driverhardcoded-keysimproper-authenticationimsinformation-disclosureinsecure-transportintegrity-bypassipseckernel-exploitmissing-access-controlpath-traversalprivilege-escalationrcesipstored-xsssupply-chainunauthenticated-rcevolteweak-cryptographyxsszip-slip

What happened

This feed contains multiple distinct, high-impact vulnerabilities across several products: Securly Chrome Extension (v3.0.7) exposes sensitive filtering data via HTTP, ships hardcoded AES passphrases, and exposes poorly obfuscated hashes allowing unauthenticated access (CVE-2026-8874, -8876, -8878, -8879); Verizon IMS/VoLTE deployments observed SIP signaling without negotiated IPsec integrity protection enabling interception/modification (CVE-2026-10629); Appsmith stored XSS in the SQL editor autocomplete that enables arbitrary JS execution for workspace members (CVE-2026-7299); Collibra Agent

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
5875a3a49cc1eb6a1330651de2b544d30c74659c1b69cedd1d995bb4fab452f7
Enrichment time
2026-06-03T20:52:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.