Security advisories disclosed multiple vulnerabilities across widely used web infrastructure components, including OWASP ModSecurity, PHP, and Roundcube Webmail. ModSecurity versions through 3.0.15 are affected by CVE-2026-52761 and CVE-2026-52747, flaws that can let attackers bypass web application firewall inspection by exploiting truncated UTF-8 processing on i386 systems and discrepancies in multipart/form-data parsing. The issues were fixed in ModSecurity 3.0.16, and defenders were advised to review rulesets that rely on input transformations and multipart inspection behavior.
PHP also published fixes for CVE-2026-12184 and CVE-2026-14355, which can trigger denial-of-service conditions in PHP-FPM and memory corruption through the OpenSSL extension’s AES-WRAP-PAD handling. Separately, Roundcube released security updates 1.6.17 and 1.7.2 for vulnerabilities affecting earlier versions of its webmail platform, with government guidance urging administrators to apply the patches. The disclosures highlight patching urgency across the web application stack, particularly for internet-facing services that depend on WAF filtering, PHP runtime stability, and webmail access.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Official PHP security advisories disclosed CVE-2026-12184 and CVE-2026-14355, which can cause denial-of-service conditions and memory corruption. PHP released patched versions for affected branches and advised organizations to upgrade.
Multiple vulnerabilities in OWASP ModSecurity, including CVE-2026-52761 and CVE-2026-52747, were disclosed as affecting versions up to 3.0.15. The flaws can enable firewall rule bypass under specific conditions and were fixed in ModSecurity version 3.0.16.
On July 5, 2026, Roundcube published security advisories for vulnerabilities affecting Roundcube Webmail. The advisories said versions prior to 1.6.17 and prior to 1.7.2 were affected, and security updates 1.6.17 and 1.7.2 were released to address the issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.