Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
OWASP CRS

OWASP CRS Vendor Cyber Rating & Cyber Score

coreruleset.org

The OWASP® CRS is a set of generic attack detection rules for use with ModSecurity or compatible web application firewalls. The CRS aims to protect web applications from a wide range of attacks, including the OWASP Top Ten, with a minimum of false alerts. The CRS provides protection against many common attack categories. We strive to make the OWASP CRS accessible to a wide audience of beginner and experienced users. We are interested in hearing any bug reports, false-positive alert reports, evasions, usability issues, and suggestions for new detections. Create an issue on GitHub to report a false positive or false negative (evasion). Please include your installed version and the relevant portions of your ModSecurity audit log. We will


OWASP CRS A.I CyberSecurity Scoring

OWASP CRS
Company Information
Website:https://coreruleset.org/
Employees number:5
Number of followers:461
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:coreruleset.org
OWASP CRS Risk Score (AI oriented)
Between 700 and 749
logo
OWASP CRSTechnology, Information and Internet
Updated:
22/04/2026
745/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
OWASP CRS Global Score (TPRM)
xxxx
logo
OWASP CRSTechnology, Information and Internet
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

OWASP CRS
OWASP CRSModerate
Current Score
745Ba (MODERATE)
01000
2 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
745Before Incident
MAY 2026
745Before Incident
APRIL 2026
745Before Incident
MARCH 2026
745Before Incident
FEBRUARY 2026
744Before Incident
JANUARY 2026
749Before Incident
Vulnerability
01 Jan 2026OWASP CRS
OWASP: Progress Software fixes sneaky WAF bypass vulnerability (CVE-2026-21876)

Progress Software Patches Critical Vulnerabilities in MOVEit WAF and LoadMaster

744After Incident
CRITICAL-5
OWA1776861154
Progress Software Patches Critical Vulnerabilities in MOVEit WAF and LoadMaster Progress Software has addressed multiple high-severity vulnerabilities in its MOVEit WAF and LoadMaster products, including a flaw that could allow attackers to bypass web application firewall (WAF) protections. The vulnerabilities affect MOVEit WAF, a security layer for the company’s managed file transfer platform (previously targeted in the 2023 Cl0p ransomware attacks), and LoadMaster, an enterprise application delivery controller with built-in WAF capabilities. Among the fixed issues: - Four OS command injection flaws (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048) enabling remote code execution by authenticated attackers. - CVE-2026-21876, a critical bug in the OWASP Core Rule Set (CRS) a widely used WAF rule framework that permits unauthenticated attackers to bypass detection via crafted HTTP multipart requests. The flaw was discovered in early January 2026 by researcher Daytrift Newgen and patched in CRS versions 4.22.0 and 3.3.8. The OWASP team described the exploit as "trivial" once known, with public proof-of-concept (PoC) code now available. Progress Software released fixes in the following versions: - MOVEit WAF v7.2.63.0 - LoadMaster v7.2.63.1 - LoadMaster LTSF v7.2.54.17 - ECS Connection Manager v7.2.63.1 - Connection Manager for ObjectScale v7.2.63.1 While no active exploitation has been reported, the company urged customers to upgrade immediately. MOVEit Cloud environments have already been patched, requiring no further action from those users. The incident underscores ongoing risks in WAF rule development and the potential for evasion techniques in security controls.
INCIDENT DETAILS -
TYPE
vulnerabilityWAF bypassremote code execution
IMPACT
MOVEit WAFLoadMasterECS Connection ManagerConnection Manager for ObjectScale
DECEMBER 2025
749Before Incident
NOVEMBER 2025
749Before Incident
OCTOBER 2025
749Before Incident
SEPTEMBER 2025
748Before Incident
AUGUST 2025
748Before Incident
JULY 2025
748Before Incident
JUNE 2025
765Before Incident
Vulnerability
16 Jun 2025OWASP CRS
OWASP ModSecurity

Denial-of-Service Vulnerability in ModSecurity WAF Engine (CVE-2025-52891)

748After Incident
MEDIUM-17
OWA950080725
A newly discovered denial-of-service vulnerability (CVE-2025-52891) in ModSecurity's WAF engine affects versions 2.9.8, 2.9.9, and 2.9.10 when SecParseXmlIntoArgs is enabled. The flaw, caused by improper handling of empty XML tags, leads to segmentation faults and complete service disruption. Exploitation requires no authentication and can be executed remotely, causing server crashes and manual restarts. While the CVSS score is moderate (6.5/10), the impact is severe for affected systems, particularly those in critical sectors like government and commercial WAF vendors. Mitigation includes disabling SecParseXmlIntoArgs or applying an upcoming patch. The vulnerability highlights ongoing security challenges in WAFs, emphasizing the need for vigilance and prompt patching.
INCIDENT DETAILS -
TYPE
Denial-of-Service
IMPACT
Systems Affected: ModSecurity WAF installationsDowntime: Server crashes requiring manual restartOperational Impact: Complete service disruption

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for OWASP CRS ?
?
What was OWASP CRS's A.I Rankiteo Cyber Score in May 2026 ?
?
What was OWASP CRS's A.I Rankiteo Cyber Score in April 2026 ?
?
What was OWASP CRS's A.I Rankiteo Cyber Score in March 2026 ?
?
What was OWASP CRS's A.I Rankiteo Cyber Score in February 2026 ?
?
What was OWASP CRS's A.I Rankiteo Cyber Score in January 2026 ?
?
What was OWASP CRS's A.I Rankiteo Cyber Score in December 2025 ?
?
What was OWASP CRS's A.I Rankiteo Cyber Score in November 2025 ?
?
What was OWASP CRS's A.I Rankiteo Cyber Score in October 2025 ?
?
What was OWASP CRS's A.I Rankiteo Cyber Score in September 2025 ?
?
What was OWASP CRS's A.I Rankiteo Cyber Score in August 2025 ?
?
What was OWASP CRS's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on OWASP CRS's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with OWASP CRS ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view OWASP CRS's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
OWASP CRS Cyber Scoring History | Rankiteo