ThreatCluster

Critical OWASP CRS Vulnerability CVE-2026-21876 Discovered

First seen 9 Jan 2026, 17:57 UTC CybersecuritynewsGbhackersCyberpress 30

Article Content

Browse articles
ThreatCluster

A critical vulnerability in the OWASP Core Rule Set (CRS), tracked as CVE-2026-21876, has been identified. This vulnerability allows attackers to bypass charset validation protections, affecting all supported versions of CRS and specifically targeting rule 922110, which is designed to block dangerous character encodings. The vulnerability has a CVSS score of 9.3, indicating its critical severity.