Atomicorp WAF Research Notes

Research Update - 2026-08-08

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2016-2386SAP NetWeaver J2EE Engine 7.40 - SQL Injection340016 , 340156 , 341245 , 380026 , 390704
CVE-2026-64638WordPress Core < 7.0.3 - Preauth Reflected XSS (XSS2Shell)344370
CVE-2026-13731WPBot <= 8.4.9 - Cross-Site Scripting346755
CVE-2020-8549WordPress Plugin Strong Testimonials 2.40.1 - Persistent Cross-Site Scripting345493 , 346755
CVE-2024-6517Contact Form 7 Math Captcha <= 2.0.1 - Cross-site Scripting346755
CVE-2020-10385WordPress Plugin WPForms 1.5.8.2 - Persistent Cross-Site Scripting345493 , 346755
CVE-2016-1910SAP NetWeaver J2EE Engine 7.40 - SQL Injection340016 , 340156 , 341245 , 380026 , 390704
CVE-2020-29475nopCommerce Store 4.30 - 'name' Stored Cross-Site Scripting346755