Atomicorp WAF Research Notes
Research Update - 2026-07-17
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
- CVE-2016-4337 - Ktools Photostore 4.7.5 - Blind SQL Injection - rules observed: 390726
- CVE-2017-16935 - Ametys CMS 4.0.2 - Password Reset - rules observed: 390724
- CVE-2017-5689 - Intel Active Management Technology - System Privileges - rules observed: 390726
- CVE-2019-25141 - Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Update - rules observed: 390726
- CVE-2022-0788 - WordPress WP Fundraising Donation and Crowdfunding Platform <1.5.0 - SQL Injection - rules observed: 390727
- CVE-2023-27350 - PaperCut - Unauthenticated Remote Code Execution - rules observed: 390727
- CVE-2022-26833 - Open Automation Software OAS Platform V16.00.0121 - Missing Authentication - rules observed: 390726
- CVE-2026-4810 - Google ADK-Python - Unauthenticated Builder Endpoint - rules observed: 390726
- CVE-2014-5308 - TestLink 1.9.11 - Multiple SQL Injections - rules observed: 390726
- CVE-2014-7884 - ArcSight Logger - Arbitrary File Upload / Code Execution - rules observed: 390726
- CVE-2014-9118 - ZHONE < S3.0.501 - Multiple Vulnerabilities - rules observed: 390726
- CVE-2017-6823 - Fiyo CMS 2.0.6.1 - Privilege Escalation - rules observed: 390724
- CVE-2024-48248 - NAKIVO Backup and Replication Solution - Unauthenticated Arbitrary File Read - rules observed: 390726
- CVE-2016-1337 - Cisco EPC 3928 - Multiple Vulnerabilities - rules observed: 390726
- CVE-2024-30188 - Apache DolphinScheduler >= 3.1.0, < 3.2.2 Resource File Read And Write - rules observed: 390726
- CVE-2014-9215 - PBBoard CMS 3.0.1 - SQL Injection - rules observed: 390726
- CVE-2018-11222 - Pandora FMS <=7.0NG.722 - Remote Code Execution - rules observed: 390726
- CVE-2018-1306 - Apache Portals Pluto 3.0.0 - Remote Code Execution - rules observed: 390727
- CVE-2015-4027 - Acunetix WVS 10 - Local Privilege Escalation - rules observed: 390726
- CVE-2025-5298 - Campcodes Online Hospital Management System 1.0 - SQL Injection - rules observed: 390726
- CVE-2011-4452 - WikkaWiki 1.3.2 - Multiple Vulnerabilities - rules observed: 390726
- CVE-2013-4865 - MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities - rules observed: 390726
- CVE-2023-45826 - Leantime < 2.4 - Authenticated SQL Injection - rules observed: 390726
- CVE-2025-54249 - Adobe Experience Manager ≤ 6.5.23.0 – SSRF - rules observed: 390726
- CVE-2025-10493 - Chained Quiz 1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie - rules observed: 390726
- CVE-2012-5877 - Nero MediaHome 4.5.8.0 - Denial of Service - rules observed: 390726
- CVE-2015-4425 - Pimcore CMS Build 3450 - Directory Traversal - rules observed: 390726
- CVE-2013-5759 - Yealink VoIP Phone SIP-T38G - Privilege Escalation - rules observed: 390726
- CVE-2026-11111 - Research note for exploit techniques associated with CVE-2026-11111 - rules observed: 340016, 340162
- CVE-2026-48907 - Research note for exploit techniques associated with CVE-2026-48907 - rules observed: 383871, 333360