Atomicorp WAF Research Notes

Research Update - 2026-07-17

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2015-1635Microsoft Windows 'HTTP.sys' - Remote Code Execution363434
CVE-2016-4337Ktools Photostore 4.7.5 - Blind SQL Injection390726 , 392647
CVE-2017-16935Ametys CMS 4.0.2 - Password Reset345493 , 390724
CVE-2017-5689Intel Active Management Technology - System Privileges390726 , 392647
CVE-2019-25141Easy WP SMTP <= 1.3.9 - Missing Authorization to Arbitrary Options Update390726 , 392647
CVE-2020-29047WP Hotel Booking < 1.10.4 - PHP Object Injection330889
CVE-2022-0788WordPress WP Fundraising Donation and Crowdfunding Platform <1.5.0 - SQL Injection340016 , 380026 , 380122 , 390727 , 392648
CVE-2023-27350PaperCut - Unauthenticated Remote Code Execution390727 , 392648
CVE-2026-35273Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCE331032
CVE-2022-26833Open Automation Software OAS Platform V16.00.0121 - Missing Authentication390726 , 392647
CVE-2026-4810Google ADK-Python - Unauthenticated Builder Endpoint390726 , 392647
CVE-2014-7884ArcSight Logger - Arbitrary File Upload / Code Execution390726 , 392647
CVE-2017-6823Fiyo CMS 2.0.6.1 - Privilege Escalation345493 , 390724
CVE-2024-48248NAKIVO Backup and Replication Solution - Unauthenticated Arbitrary File Read344360 , 390726 , 392647
CVE-2024-30188Apache DolphinScheduler >= 3.1.0, < 3.2.2 Resource File Read And Write340162 , 340165 , 344360 , 347009 , 390726 , 392647
CVE-2018-11222Pandora FMS <=7.0NG.722 - Remote Code Execution390726 , 392647
CVE-2018-1306Apache Portals Pluto 3.0.0 - Remote Code Execution390727 , 392648
CVE-2015-4027Acunetix WVS 10 - Local Privilege Escalation330791 , 340152 , 390726 , 392647
CVE-2025-5298Campcodes Online Hospital Management System 1.0 - SQL Injection390726 , 392647
CVE-2013-4865MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities330791 , 340121 , 340152 , 344360 , 344370 , 390636 , 390726 , 392647
CVE-2023-45826Leantime < 2.4 - Authenticated SQL Injection340017 , 340159 , 341245 , 390726 , 392647
CVE-2025-54249Adobe Experience Manager ≤ 6.5.23.0 – SSRF390726 , 392647
CVE-2025-10493Chained Quiz 1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie390726 , 392647
CVE-2015-4425Pimcore CMS Build 3450 - Directory Traversal390726 , 392647