CVE-2026-103932 concerns improper PCRE2 error handling in ModSecurity's @rxGlobal operator. Reaching a regular-expression match limit can cause processing to fail open, allowing requests to bypass intended security checks. An invalid pattern can also crash the affected process. Assessment metadata associates the vulnerability with ModSecurity packages on Ubuntu and Debian, without specifying affected ModSecurity versions. The listed Amazon Linux 2, Amazon Linux 2023, and Amazon Linux 2027 Preview mod_security packages are explicitly identified as unaffected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ModSecurity @rxGlobal PCRE2 error-handling vulnerability involving fail-open behavior when a match limit is reached and crashes triggered by invalid patterns. The reference rates it Medium with a CVSS v3.1 score of 5.8. Amazon Linux 2, Amazon Linux 2023, and Amazon Linux 2027 Preview mod_security packages are explicitly listed as not affected.
An unpatched vulnerability affecting ModSecurity packages on Ubuntu and Debian. The supplied CVSS vector indicates a network-accessible, low-complexity attack requiring no privileges or user interaction, with high availability impact and no confidentiality or integrity impact. The content does not describe the underlying flaw.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.