Sploitus

CVE-2026-52761

No indexed exploits for CVE-2026-52761 yet

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in src/actions/transformations/utf8_to_unicode.cc produces wrong output on i386 architecture because snprintf uses sizeof on a char pointer rather than the length of the unicode buffer, allowing rules that use this transformation to be bypassed on i386 architecture. This issue is fixed in version 3.0.16.

Affected products
Modsecurity
Owasp Modsecurity
≤ 3.0.15
Fix
Available
CVSS 3.1
5.8 MEDIUM
EPSS
0.4% (34th percentile)
Weakness
CWE-467
NVD status
Analyzed
Published
2026-07-10
CVE-2026-52761 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-52761 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-52761 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.