CVE•Published 2026-06-03•Modified 2026-07-22•0 articles on news•5 live references•NVD data
CVE-2026-8888Securly · Securly
Vulnerability data via NVD (ingested)
CVSS v3.1
7.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS percentile
35
Exploit Prediction Scoring System · top 65% of all CVEs
Weaknesses (CWE)
Description
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.
Timeline
Published 2026-06-03
Modified 2026-07-22
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2026-8888Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product + version
product:"Securly Securly" version:"3.0.7"Version-pinned fingerprint from NVD's first vulnerable CPE.
Shodan · banner/body mention
http.html:"Securly"HTTP body or banner mentions "Securly" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-8888Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-8888Censys host search filtered to this CVE id.
grep.app
CVE-2026-8888Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-8888GitHub code search for direct mentions.
Google dork
"CVE-2026-8888" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (8)
CVE-2026-88888 repos
0xSteph/pentest-aiPython
Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.
Cyber-note/Full-Bug-Bounty-Hunting-Methodology-2026unknown
How To approach recon on real targets — from passive enumeration to origin IP discovery. Covers tools, automation, and the logic behind each phase.
grisuno/LazyOwnPython
LazyOwn RedTeam/APT Framework is the first RedTeam Framework with an AI-powered C&C, featuring rootkits to conceal campaigns, undetectable malleable implants compatible with Window…
7WaySecurity/ai_osintunknown
🤖 Curated AI OSINT resources — Google dorks, Shodan queries, GitHub dorks, and techniques to discover exposed LLM endpoints, leaked AI API keys, misconfigured vector databases, an…
fstr415/TikTok-Poll-Voting-ExploitJavaScript
Modern day TikTok exploit that allows you to fake having the "Voted on" text under any tiktok for anyone to see, no matter if the tiktok has the poll or not. Anything you want can …
3sk1nt4n/arguswatch-aiPython
AI-Agentic Threat Intelligence - 39 collectors, 7 AI agents, 3-link proof chain, D1-D5 exposure scoring
yks0000/starred-repo-tocGo
Generates Markdown table for all Starred Repositories by a GitHub user.
lsszz2100/VibeHackingJavaScript
A Collection of Repositories, Videos, Books, and Lecture Materials to Learn Security & Hacking with AI in a Fun Way
We haven't classified any articles referencing CVE-2026-8888 yet. The external references above still apply.