OWASP CRS A.I CyberSecurity Scoring
OWASP CRS
Company Information
Website:https://coreruleset.org/
Employees number:5
Number of followers:461
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:coreruleset.org
OWASP CRS Risk Score (AI oriented)
Between 700 and 749
OWASP CRSTechnology, Information and Internet
Updated:
22/04/2026
22/04/2026
745/1000
Moderate
Ba
OWASP CRS Global Score (TPRM)
xxxx
OWASP CRSTechnology, Information and Internet
Score locked

OWASP CRSModerate
Current Score
745Ba (MODERATE)
01000
2 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
745
MAY 2026
745
APRIL 2026
745
MARCH 2026
745
FEBRUARY 2026
744
JANUARY 2026
749
Vulnerability
01 Jan 2026 • OWASP CRS
OWASP: Progress Software fixes sneaky WAF bypass vulnerability (CVE-2026-21876)
Progress Software Patches Critical Vulnerabilities in MOVEit WAF and LoadMaster
744
CRITICAL-5
OWA1776861154
Progress Software Patches Critical Vulnerabilities in MOVEit WAF and LoadMaster
Progress Software has addressed multiple high-severity vulnerabilities in its MOVEit WAF and LoadMaster products, including a flaw that could allow attackers to bypass web application firewall (WAF) protections.
The vulnerabilities affect MOVEit WAF, a security layer for the company’s managed file transfer platform (previously targeted in the 2023 Cl0p ransomware attacks), and LoadMaster, an enterprise application delivery controller with built-in WAF capabilities. Among the fixed issues:
- Four OS command injection flaws (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048) enabling remote code execution by authenticated attackers.
- CVE-2026-21876, a critical bug in the OWASP Core Rule Set (CRS) a widely used WAF rule framework that permits unauthenticated attackers to bypass detection via crafted HTTP multipart requests. The flaw was discovered in early January 2026 by researcher Daytrift Newgen and patched in CRS versions 4.22.0 and 3.3.8. The OWASP team described the exploit as "trivial" once known, with public proof-of-concept (PoC) code now available.
Progress Software released fixes in the following versions:
- MOVEit WAF v7.2.63.0
- LoadMaster v7.2.63.1
- LoadMaster LTSF v7.2.54.17
- ECS Connection Manager v7.2.63.1
- Connection Manager for ObjectScale v7.2.63.1
While no active exploitation has been reported, the company urged customers to upgrade immediately. MOVEit Cloud environments have already been patched, requiring no further action from those users. The incident underscores ongoing risks in WAF rule development and the potential for evasion techniques in security controls.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
DECEMBER 2025
749
NOVEMBER 2025
749
OCTOBER 2025
749
SEPTEMBER 2025
748
AUGUST 2025
748
JULY 2025
748
JUNE 2025
765
Vulnerability
16 Jun 2025 • OWASP CRS
OWASP ModSecurity
Denial-of-Service Vulnerability in ModSecurity WAF Engine (CVE-2025-52891)
748
MEDIUM-17
OWA950080725
A newly discovered denial-of-service vulnerability (CVE-2025-52891) in ModSecurity's WAF engine affects versions 2.9.8, 2.9.9, and 2.9.10 when SecParseXmlIntoArgs is enabled. The flaw, caused by improper handling of empty XML tags, leads to segmentation faults and complete service disruption. Exploitation requires no authentication and can be executed remotely, causing server crashes and manual restarts. While the CVSS score is moderate (6.5/10), the impact is severe for affected systems, particularly those in critical sectors like government and commercial WAF vendors. Mitigation includes disabling SecParseXmlIntoArgs or applying an upcoming patch. The vulnerability highlights ongoing security challenges in WAFs, emphasizing the need for vigilance and prompt patching.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for OWASP CRS ??
What was OWASP CRS's A.I Rankiteo Cyber Score in May 2026 ??
What was OWASP CRS's A.I Rankiteo Cyber Score in April 2026 ??
What was OWASP CRS's A.I Rankiteo Cyber Score in March 2026 ??
What was OWASP CRS's A.I Rankiteo Cyber Score in February 2026 ??
What was OWASP CRS's A.I Rankiteo Cyber Score in January 2026 ??
What was OWASP CRS's A.I Rankiteo Cyber Score in December 2025 ??
What was OWASP CRS's A.I Rankiteo Cyber Score in November 2025 ??
What was OWASP CRS's A.I Rankiteo Cyber Score in October 2025 ??
What was OWASP CRS's A.I Rankiteo Cyber Score in September 2025 ??
What was OWASP CRS's A.I Rankiteo Cyber Score in August 2025 ??
What was OWASP CRS's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on OWASP CRS's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with OWASP CRS ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view OWASP CRS's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?