CVE-2026-21876Patch(owasp / owasp_modsecurity_core_rule_set)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch owasp owasp_modsecurity_core_rule_set systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests with multiple parts. When the first rule in a chain iterates over a collection (like `MULTIPART_PART_HEADERS`), the capture variables (`TX:0`, `TX:1`) get overwritten with each iteration. Only the last captured value is available to the chained rule, which means malicious charsets in earlier parts can be missed if a later part has a legitimate charset. Versions 4.22.0 and 3.3.8 patch the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-794

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • owasp_modsecurity_core_rule_set

Threat summary

  • Patch or workaround signal is available
  • 13 mentions across 6 observed days
  • Momentum state: rising

What's happening

  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 9 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 6 mentions (2026-04-22); latest day: 1
  • 13 total mentions across 6 days

Affected systems

Vendors
Products
owasp_modsecurity_core_rule_set

Deep dive

Activity timeline13 mentions / 6d
02356Mentions · 2026-02-01: 1Mentions · 2026-02-19: 1Mentions · 2026-02-22: 1Mentions · 2026-04-22: 6Mentions · 2026-05-01: 3Mentions · 2026-06-02: 1Patch / Workaround · 2026-02-01: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-22: 1Patch / Workaround · 2026-04-22: 6Patch / Workaround · 2026-05-01: 3Technical Details · 2026-02-01: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-22: 1Technical Details · 2026-04-22: 3Technical Details · 2026-05-01: 302-0102-1902-2204-2205-0106-02
Signal classification2 categories
Patch
1292.3%
Disclosure
17.7%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-011
Patch1
2026-02-191
Patch1
2026-02-221
Patch1
2026-04-226
Patch6
2026-05-013
Patch3
2026-06-021
Disclosure1
Full discourse13 posts
  • reverseame@reverseame
    Patch

    CVE-2026-21876: Critical Multipart Charset Bypass Fixed in CRS 4.22.0 and 3.3.8 https://coreruleset.org/20260106/cve-2026-21876-critical-multipart-charset-bypass-fixed-in-crs-4.22.0-and-3.3.8/

    Post summary

    The announcement declares that CVE-2026-21876, a critical multipart charset bypass vulnerability, has been fixed in CRS versions 4.22.0 and 3.3.8.

    00233999
    22.4K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Patch

    Progress Software fixes sneaky WAF bypass vulnerability (CVE-2026-21876) https://www.helpnetsecurity.com/2026/04/22/progress-waf-bypass-cve-2026-21876/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The text announces a patch released by Progress Software for CVE-2026-21876, a WAF bypass vulnerability.

    01010654
    194.5K followersView on X
  • cPanel@cPanel
    Patch

    EasyApache 4 v25.46 is out: ✨ OWASP CRS 3.3.8 (fixes CVE-2026-21876) ✨ NGINX 1.29.5 (fixes CVE-2026-1642) ✨ NGINX modules rebuilt for 1.29.5 compatibility Changelog: #EasyApache #cPanelUpdates https://t.co/NBOvWyarOH

    Post summary

    EasyApache 4 v25.46 release includes patches for CVE‑2026‑21876 (via OWASP CRS 3.3.8) and CVE‑2026‑1642 (via NGINX 1.29.5), updating related modules accordingly.

    10010293
    28.7K followersView on X
  • Blue Team News@blueteamsec1
    Disclosure

    MOVEit WAF Critical Security Bulletin – April 2026 – (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048, CVE-2026-21876) http://dlvr.it/TSqvhx #cyber #threathunting #infosec

    Post summary

    The text announces MOVEit WAF’s critical security bulletin listing five CVEs, focusing on disclosure rather than PoC, exploit, or patch information.

    00000502
    56.1K followersView on X
  • Yasir Raza@yasirrazahaidry
    Patch

    The critical CVE-2026-21876 multipart charset bypass has been fixed in CRS 4.22.0 and 3.3.8 Source: https://x.com/reverseame/status/2050177948141891820

    Post summary

    The tweet announces that CVE‑2026‑21876, a multipart charset bypass, has been patched in CRS 4.22.0 and 3.3.8, with no evidence of ongoing exploitation or PoC.

    0000038
    908 followersView on X
  • Yasir Raza@yasirrazahaidry
    Patch

    CRS 4.22.0 & 3.3.8 patch critical CVE-2026-21876 multipart charset bypass. Source: https://x.com/reverseame/status/2050177948141891820

    Post summary

    The tweet announces that a critical patch is available for CVE-2026-21876, which addresses a multipart charset bypass in CRS 4.22.0 and 3.3.8.

    0000062
    908 followersView on X
  • キタきつね@foxbook
    Patch

    Progress Software社が、巧妙なWAFバイパスの脆弱性(CVE-2026-21876)を修正しました Progress Software fixes sneaky WAF bypass vulnerability (CVE-2026-21876) #HelpNetSecurity (Apr 22) https://www.helpnetsecurity.com/2026/04/22/progress-waf-bypass-cve-2026-21876/

    Post summary

    Progress Software has issued a fix for the WAF bypass vulnerability CVE-2026-21876; no PoC, exploit, active exploitation, or technical details are provided.

    00000238
    4.8K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Progress patches multiple critical vulnerabilities in MOVEit WAF and Progress Kemp LoadMaster! This includes CVE-2026-21876 which allows attackers to bypass the WAF! More info: https://community.progress.com/s/article/MOVEit-WAF-Critical-Security-Bulletin-April-2026-CVE-2026-3517-CVE-2026-3518-CVE-2026-3519-CVE-2026-4048-CVE-2026-21876 #patch #patch #patch

    Post summary

    The post warns that Progress has issued patches for several critical vulnerabilities, including CVE-2026-21876 which permits WAF bypass, and provides a link to the detailed bulletin.

    00000244
    7.2K followersView on X
  • ScyScan@ScyScan
    Patch

    #Progress Software fixes sneaky #WAF bypass vulnerability (#CVE-2026-21876) https://www.scyscan.com/news/progress-software-fixes-sneaky-waf-bypass-vulnerability-cve-2026-21876/

    Post summary

    The post reports that Progress Software has addressed a WAF bypass flaw identified as CVE‑2026‑21876, citing a news article but providing no details on exploits or active attacks.

    0000048
    61 followersView on X
  • Help Net Security@helpnetsecurity
    Patch

    Progress Software fixes sneaky WAF bypass vulnerability (CVE-2026-21876) - https://www.helpnetsecurity.com/2026/04/22/progress-waf-bypass-cve-2026-21876/ - @ProgressSW @owasp @CoreRuleSet #Enterprise #Firewall #SecurityUpdate #vulnerability #WebApplicationSecurity #Cybersecurity #CybersecurityNews https://t.co/oLL90mNOND

    Post summary

    The tweet announces that Progress Software has released a fix for the CVE‑2026‑21876 WAF bypass vulnerability, without providing any PoC, exploit, or technical details.

    00000390
    60.1K followersView on X
  • Shah Sheikh@shah_sheikh
    Patch

    Progress Software fixes sneaky WAF bypass vulnerability (CVE-2026-21876): Progress Software has fixed a slew of high-severity vulnerabilities in MOVEit WAF and LoadMaster, including a flaw (CVE-2026-21876) that may allow attackers to bypass firewall… https://www.helpnetsecurity.com/2026/04/22/progress-waf-bypass-cve-2026-21876/?utm_source=dlvr.it&utm_medium=twitter https://t.co/VYpzW7t7b1

    Post summary

    Progress Software has released a patch for the high‑severity MOVEit WAF bypass vulnerability CVE‑2026‑21876; the article provides technical details of the flaw but no evidence of active exploitation or a PoC.

    0000062
    2.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 #Debian LTS DLA-4488-1: Critical ModSecurity CRS patches released Fixes 2 high-impact WAF bypasses: 🔹 CVE-2023-38199: "Content-Type confusion" attacks. 🔹 CVE-2026-21876: Multipart request parsing logic flaw. Read mroe: 👉 https://tinyurl.com/42jjnmt4 #Security https://t.co/DmRCBv8Fmm

    Post summary

    Debian LTS released patches for two high‑impact ModSecurity CRS vulnerabilities, CVE‑2023‑38199 and CVE‑2026‑21876, addressing content‑type confusion and multipart parsing flaws.

    00000121
    1.3K followersView on X
  • fernand0@fernand0
    Patch

    CVE-2026-21876: Critical Multipart Charset Bypass Fixed in CRS 4.22.0 and 3.3.8 https://coreruleset.org/20260106/cve-2026-21876-critical-multipart-charset-bypass-fixed-in-crs-4.22.0-and-3.3.8/

    Post summary

    The advisory announces that CVE-2026-21876, a critical multipart charset bypass vulnerability, has been fixed in CRS 4.22.0 and 3.3.8.

    00000114
    6.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appowaspowasp_modsecurity_core_rule_set---

Explore more