logo

Progress Software fixes sneaky WAF bypass vulnerability (CVE-2026-21876)

ID: f6c13a09-49cf-53cf-973d-0b5e05c7838d

STIX ID: report--f6c13a09-49cf-53cf-973d-0b5e05c7838d

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-04-22

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

Progress Software released patches for five high-severity flaws affecting MOVEit WAF and Kemp LoadMaster, including four authenticated OS command injection vulnerabilities that can lead to remote code execution (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048) and a critical OWASP CRS bug (CVE-2026-21876) that enables unauthenticated WAF detection bypass via crafted multipart HTTP requests; PoC exploits for the bypass are public and customers are strongly urged to upgrade to the fixed versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.