Multiple ModSecurity Vulnerabilities Allow Attackers to Bypass Firewall Rules
Multiple vulnerabilities have been disclosed in OWASP ModSecurity, a widely used open-source web application firewall (WAF), allowing attackers to bypass security rules under specific conditions. The flaws, tracked as CVE-2026-52761 and CVE-2026-52747, affect ModSecurity versions up to 3.0.15 and have been addressed in version 3.0.16. The first issue, CVE-2026-52761, is a moderate-severity flaw that impacts […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
