CVE-2026-33691
published 2026-04-02CVE-2026-33691: The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0…
PriorityP359high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EXPLOIT
EPSS
3.58%
88.2th percentile
The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). The affected rules do not normalize whitespace before evaluating the file extension regex, so the dot-extension check fails to match. This issue has been patched in versions 3.3.9 and 4.25.0.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coreruleset | coreruleset | < 3.3.9 | 3.3.9 |
| coreruleset | coreruleset | — | — |
| debian | modsecurity-crs | < modsecurity-crs 3.3.9-1 (forky) | modsecurity-crs 3.3.9-1 (forky) |
| owasp | owasp_modsecurity_core_rule_set | < 3.3.9 | 3.3.9 |
| owasp | owasp_modsecurity_core_rule_set | >= 4.0.0 < 4.25.0 | 4.25.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_debian6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-33691: The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls
osv·2026-04-02·CVSS 7.5
CVE-2026-33691 [HIGH] CVE-2026-33691: The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls
The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). The affected rules do not normalize whitespace before evaluating the file extension regex, so the dot-extension check fails to match. This issue has been patched in versions 3.3.9 and 4.25.0.
OSV
CVE-2026-33691: [Whitespace padding in filenames bypasses file upload extension checks]
osv·2026-03-31·CVSS 7.5
CVE-2026-33691 [HIGH] CVE-2026-33691: [Whitespace padding in filenames bypasses file upload extension checks]
[Whitespace padding in filenames bypasses file upload extension checks]
Debian
CVE-2026-33691: modsecurity-crs - The OWASP core rule set (CRS) is a set of generic attack detection rules for use...
vendor_debian·2026·CVSS 6.8
CVE-2026-33691 [MEDIUM] CVE-2026-33691: modsecurity-crs - The OWASP core rule set (CRS) is a set of generic attack detection rules for use...
The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). The affected rules do not normalize whitespace before evaluating the file extension regex, so the dot-extension check fails to match. This issue has been patched in versions 3.3.9 and 4.25.0.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.3.9-1)
sid: resolved (fixed in 3.3.9-1)
trixie: open
No detection rules found.
Nuclei
Progress ADC LoadMaster - Command Injection
nuclei·CVSS 7.5
CVE-2026-8037 [HIGH] Progress ADC LoadMaster - Command Injection
Progress ADC LoadMaster - Command Injection
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
Template:
id: CVE-2026-8037
info:
name: Progress ADC LoadMaster - Command Injection
author: watchtowr,DhiyaneshDk
severity: critical
description: |
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
impact: |
Unauthenticated attackers can execute arbitrary commands on the LoadMaster appliance, potentially leadin
Hackernews
Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
blogs_hackernews·2026-06-30·CVSS 9.6
CVE-2026-8037 [CRITICAL] Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API.
The flaw, tracked as CVE-2026-8037 , carries a CVSS score of 9.8 according to ZDI . A patch is available. If you run LoadMaster with the API enabled, update now.
Progress published its advisory on June 4 and says it has not received any reports of exploitation. On June 29, researchers at watchTowr Labs published a detailed technical write-up that walks through the full
Wiz
CVE-2026-33691 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-33691 [MEDIUM] CVE-2026-33691 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33691 :
Linux Debian vulnerability analysis and mitigation
The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). The affected rules do not normalize whitespace before evaluating the file extension regex, so the dot-extension check fails to match. This issue has been patched in versions 3.3.9 and 4.25.0.
Source : NVD
## 6.8
Score
Published April 2, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
Linux Debian
Echo
Has Public Exploit No
Has CISA KEV Exploit
https://github.com/coreruleset/coreruleset/commit/2a8c63512811c5dd74472becebb79a783e68ff02https://github.com/coreruleset/coreruleset/pull/4546https://github.com/coreruleset/coreruleset/pull/4547https://github.com/coreruleset/coreruleset/pull/4548https://github.com/coreruleset/coreruleset/releases/tag/v3.3.9https://github.com/coreruleset/coreruleset/releases/tag/v4.25.0https://github.com/coreruleset/coreruleset/security/advisories/GHSA-rw5f-9w43-gv2whttp://seclists.org/fulldisclosure/2026/Apr/0http://www.openwall.com/lists/oss-security/2026/03/29/2http://www.openwall.com/lists/oss-security/2026/04/18/4
2026-04-02
Published