CVE-2026-33691Disclosure(owasp / owasp_modsecurity_core_rule_set)

HIGHCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch owasp owasp_modsecurity_core_rule_set systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). The affected rules do not normalize whitespace before evaluating the file extension regex, so the dot-extension check fails to match. This issue has been patched in versions 3.3.9 and 4.25.0.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-178

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • owasp_modsecurity_core_rule_set

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 11 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 10d ago at 4 mentions (2026-03-30); latest day: 1
  • 14 total mentions across 11 days

Affected systems

Vendors
Products
owasp_modsecurity_core_rule_set

Deep dive

Activity timeline14 mentions / 11d
01234Mentions · 2026-03-30: 4Mentions · 2026-04-02: 1Mentions · 2026-04-03: 1Mentions · 2026-04-10: 1Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-04-19: 1Mentions · 2026-06-06: 1Mentions · 2026-06-19: 1Mentions · 2026-07-13: 1Mentions · 2026-08-11: 1PoC Mentioned / Linked · 2026-04-17: 1PoC Mentioned / Linked · 2026-04-18: 1PoC Mentioned / Linked · 2026-08-11: 1Exploit Tool / Code · 2026-08-11: 1Active Exploitation · 2026-08-11: 1Patch / Workaround · 2026-03-30: 2Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-08-11: 1Technical Details · 2026-03-30: 3Technical Details · 2026-04-03: 1Technical Details · 2026-04-19: 1Technical Details · 2026-08-11: 103-3004-0204-0304-1004-1704-1804-1906-0606-1907-1308-11
Signal classification5 categories
Disclosure
535.7%
Patch
428.6%
General
214.3%
PoC
214.3%
Active Exploitation
17.1%
Referenced assets22 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-304
Disclosure2Patch2
2026-04-021
Disclosure1
2026-04-031
General1
2026-04-101
Patch1
2026-04-171
PoC1
2026-04-181
PoC1
2026-04-191
Disclosure1
2026-06-061
Patch1
2026-06-191
Disclosure1
2026-07-131
General1
2026-08-111
Active Exploitation1
Full discourse14 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-33691: OWASP CRS whitespace padding bypass vulnerability https://openwall.com/lists/oss-security/2026/03/29/2 Whitespace padding in filenames can bypass file upload extension checks, allowing uploads of dangerous files such as .php, .phar, .jsp, and .jspx. Exploitation is most practical on Windows.

    Post summary

    CVE-2026-33691 is a disclosed OWASP CRS vulnerability that uses whitespace padding to bypass file upload extension checks, enabling dangerous uploads on Windows. No PoC, exploit code, patch, or evidence of active exploitation is provided.

    000104647
    4.4K followersView on X
  • Core Rule Set@CoreRuleSet
    Patch

    🔒 Security Advisory: OWASP CRS file upload extension checks could be bypassed using whitespace padding in filenames (e.g. shell. php). CVE-2026-33691, Moderate severity. Upgrade to CRS v4.25.0 or v3.3.9. Thanks @HackingRepo for the report! https://github.com/coreruleset/coreruleset/security/advisories/GHSA-rw5f-9w43-gv2w

    Post summary

    The advisory exposes a file‑upload bypass in OWASP CRS using whitespace padding, recommends upgrading to specific CRS versions for mitigation, and provides no evidence of exploitation or exploit code.

    04041320
    1.2K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(08/07追加) #vulnerability 🛡CVE-2026-8037 Progress LoadMaster Command Injection Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / NVD ・種別:コマンドインジェクション (CWE-77) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Progress LoadMaster、ECS Connection Manager、Object Scale Connection Manager、MOVEit WAF に存在する OS コマンドインジェクションの脆弱性です。 未認証の攻撃者が、複数のコマンドエンドポイントにおけるサニタイズ不備を悪用し、LoadMaster アプライアンス上で任意コマンドを実行できる可能性があります。 影響を受ける LoadMaster は GA 7.2.63.1 以前、および LTSF 7.2.54.17 以前であり、修正バージョンは GA 7.2.63.2 および LTSF 7.2.54.18 です。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は困難 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月10日 ・BOD 26-04 対処期限(露出なし):2026年8月21日 ✅攻撃前提条件 ・Progress LoadMaster、ECS Connection Manager、Object Scale Connection Manager、または MOVEit WAF を使用している ・LoadMaster GA 7.2.63.1 以前、または LTSF 7.2.54.17 以前を使用している ・攻撃者が対象製品の API エンドポイントへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・API が有効化されている ・修正済みバージョンへ更新されていない ✅悪用時影響 ・未認証の攻撃者に任意コマンドを実行される可能性がある ・LoadMaster アプライアンス上でリモートコード実行につながる可能性がある ・root 権限相当でコマンドを実行される可能性がある ・ロードバランサーやADCを起点に内部ネットワークへの追加侵害につなげられる可能性がある ・機密性、完全性、可用性に高い影響が生じる ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:確認済み(eSentire) ・概要:eSentire Threat Response Unit は、2026年6月29日から CVE-2026-8037 を標的とする悪用試行を確認したと公表 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-8037 ・https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691 ・https://docs.progress.com/bundle/release-notes_loadmaster-7-2-63-2/page/Security-Updates.html ・https://docs.progress.com/bundle/release-notes_loadmaster-7-2-54-18/page/Security-Updates.html ・https://github.com/cisagov/vulnrichment/blob/develop/2026/8xxx/CVE-2026-8037.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8037 ・https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/ ・https://www.esentire.com/security-advisories/progress-kemp-loadmaster-vulnerability-targeted-cve-2026-8037 ・https://jvndb.jvn.jp/ja/cwe/CWE-77.html CISA Alert ・https://www.cisa.gov/news-events/alerts/2026/08/07/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    CVE‑2026‑8037 is a critical OS command injection in Progress LoadMaster products, actively exploited in the wild with PoC and exploit code available, and patches have been released; CISA has catalogued it as a known exploited vulnerability.

    000425.5K
    45.6K followersView on X
  • cPanel@cPanel
    Patch

    EasyApache 4 v25.53 is now available: • Tomcat → 10.1.54 • re2c → 4.5.1 • rubygem-rack → 2.2.23 (CVE-2026-34830, CVE-2026-34785) • OWASP CRS → 3.3.9 (CVE-2026-33691) • ea-cpanel-tools updated Full change log → https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ #EasyApache #cPanelUpdates https://t.co/K7TLrVp57m

    Post summary

    The tweet announces a new EasyApache 4 release that patches several CVEs by upgrading components such as Tomcat, re2c, rack, and OWASP CRS, and links to the full changelog.

    11130355
    28.7K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Progress ❗ CVE-2026-8037 ❗ CVE-2026-33691 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-progress-3/ https://t.co/4dzHP34ERB

    Post summary

    The tweet announces two CVEs affecting Progress products and links to an external source for additional information, but does not provide PoC, exploit details, patch information, or technical specifics.

    00010247
    6.7K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos Progress ❗ CVE-2026-8037 ❗ CVE-2026-33691 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-progress-2/ https://t.co/JlAMWbyS2X

    Post summary

    The post announces two new CVEs (CVE‑2026‑8037 and CVE‑2026‑33691) affecting Progress products and directs readers to external links for more information.

    00000102
    6.7K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Progress issued a LoadMaster security bulletin on two flaws CVE-2026-8037 and CVE-2026-33691 disclosed in June 2026, according to Canada's Cyber Centre. https://threatcluster.io/cluster/critical-vulnerabilities-addressed-in-progress-and-hpe-produ-8f851d28

    Post summary

    The text reports that Progress released a LoadMaster security bulletin addressing two vulnerabilities (CVE-2026-8037 and CVE-2026-33691) disclosed in June 2026, with no indication of exploitation or artifact details.

    0000073
    313 followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    "CVE-2026-33691: OWASP CRS whitespace padding bypass vulnerability" determined not to be limited to Windows, but also affect Linux, etc. https://www.openwall.com/lists/oss-security/2026/04/16/12

    Post summary

    The post announces that CVE-2026-33691, an OWASP CRS whitespace padding bypass vulnerability, also affects Linux in addition to Windows.

    00000202
    4.5K followersView on X
  • cyber security@relimsec
    PoC

    I just published Turn Off Security Headers using CVE-2026–33691 https://medium.com/p/turn-off-security-headers-using-cve-2026-33691-322625f2780f?source=social.tw

    Post summary

    The post announces a Medium article detailing a method to exploit CVE-2026‑33691, suggesting a PoC exists but provides no further technical or exploit tool specifics.

    0000036
    2 followersView on X
  • cyber security@relimsec
    PoC

    I just published Disable ModSecurity WAF using CVE-2026–33691 https://medium.com/p/disable-modsecurity-waf-using-cve-2026-33691-7d0e88919dfc?source=social.tw

    Post summary

    The author has posted a Medium article that claims to disable ModSecurity WAF via CVE-2026-33691, indicating a PoC is available, but no additional exploit or mitigation details are provided in the excerpt.

    0000048
    1 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: [CVE-2026-33691] OWASP CRS whitespace padding bypassvulnerability Intel Report: https://ift.tt/C72N4cM

    Post summary

    The alert references CVE-2026-33691, labeling it as an OWASP CRS whitespace padding bypass vulnerability and linking to an Intel Report, but it provides no information on patches, exploitation, PoC, or tooling.

    0000045
    281 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33691 The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypa… https://www.cve.org/CVERecord?id=CVE-2026-33691

    Post summary

    The text announces CVE‑2026‑33691, a bypass vulnerability in the OWASP Core Rule Set, and indicates that newer versions (≥3.3.9 and 4.25.0) contain the patch.

    0000061
    56.9K followersView on X
  • cyber security@relimsec
    Disclosure

    CVE-2026-33691 i found it on CRS, it is about using whitespace padding to bypass WAFs that uses CRS to upload a malicious file that leads to RCE if the app vulnerable. Full advisory: https://github.com/coreruleset/coreruleset/security/advisories/GHSA-rw5f-9w43-gv2w

    Post summary

    The post references CVE‑2026‑33691 and outlines a whitespace‑padding bypass that can lead to remote code execution, but lacks exploit code, evidence of active exploitation, or patch information.

    0000055
    1 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-mod_security_crs Module Update 4.25.0-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: mod_security_crs 4.25.0-1 This update includes support for vulnerability(CVE-2026-33691). The module update can be... https://kusanagi.tokyo/en/releases/23920/

    Post summary

    Kusanagi released an updated mod_security_crs module that includes a fix for CVE-2026-33691; no PoC, exploit, or active exploitation details are provided.

    0000049
    200 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appowaspowasp_modsecurity_core_rule_set---

Explore more