Atomicorp WAF Research Notes
Research Update - 2026-07-23
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
- CVE-2026-46442 - Flowise < 3.1.2 - node-custom-function Unauthorized RCE - rules observed: 345240
- CVE-2026-6875 - ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE - rules observed: 380026
- CVE-2026-54836 - YMC Filter - SQL Injection - rules observed: 380122
- CVE-2026-9282 - W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read - rules observed: 344360
- CVE-2025-29635 - D-Link DIR-823X set_prohibiting - Command Injection - rules observed: 340014
- CVE-2021-47795 - GeoVision GeoWebServer <= 5.3.3 - Local File Inclusion / Cross-Site Scripting - rules observed: 341266, 390716
- CVE-2026-8385 - WordPress WP Go Maps < 10.0.10 - Unauthenticated Marker Data Disclosure - rules observed: 344365
- CVE-2026-11111 - Research note for exploit techniques associated with CVE-2026-11111 - rules observed: 340016, 340162
- CVE-2026-15094 - WP Hotel Booking <= 2.3.2 - Cross-Site Scripting - rules observed: 300002
- CVE-2026-48907 - Research note for exploit techniques associated with CVE-2026-48907 - rules observed: 383871, 333360
- CVE-2026-60137 - Pre-existing generic rules block the WordPress author__not_in SQL injection - rules observed: 340156, 344370
- CVE-2026-63030 - Pre-existing generic rules disrupt the WordPress route-confusion SQL injection chain - rules observed: 340156, 344370