Skip to content
ThreatCluster

Critical OWASP CRS Vulnerability CVE-2026-21876 Discovered

First seen 9 Jan 2026, 17:57 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A critical vulnerability in the OWASP Core Rule Set (CRS), tracked as CVE-2026-21876, has been identified. This vulnerability allows attackers to bypass charset validation protections, affecting all supported versions of CRS and specifically targeting rule 922110, which is designed to block dangerous character encodings. The vulnerability has a CVSS score of 9.3, indicating its critical severity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track CVE-2026-21876 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed