Atomicorp WAF Research Notes
Research Update - 2026-08-25
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-51366 | Bottinelli Informatica Vedo Suite v.1.2.5 Arbitrary Code Execution Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2023-25826 | OpenTSDB <= 2.4.1 - Unauthenticated RCE via Gnuplot Injection | 340029 , 344363 , 390722 |
| CVE-2024-31823 | ecommerce-codeigniter-bootstrap Arbitrary Code Execution Vulnerability | 344360 |
| CVE-2025-14998 | Branda WordPress plugin - Privilege Escalation | 377360 |
| CVE-2026-11387 | SMS Alert – SMS & OTP for WooCommerce - Privilege Escalation | 377360 |
| CVE-2026-19598 | Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX Router | 377360 |
| CVE-2026-71921 | DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-76070 | Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-76071 | Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-73570 | zimbra collaboration suite Arbitrary Code Execution Vulnerability | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-76842 | Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Payment Clients | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-79662 | Ech0 before 4.7.3 OAuth Redirect URI Validation Bypass | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-34100 | Guardian Language-System SQL Injection via id Parameter in media.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-34101 | Guardian Language-System SQL Injection via id Parameter in text_file.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-34102 | Guardian Language-System SQL Injection via id Parameter in job_info_get.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-34103 | Guardian Language-System SQL Injection via id Parameter in subtitles.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-34104 | Guardian Language-System SQL Injection via name Parameter in designer.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-34105 | Guardian Language-System SQL Injection via id Parameter in translate_text.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-57863 | Crater Invoice 6.0.6 Path Traversal RCE via update/unzip endpoint | 340007 , 344360 , 390709 |
| CVE-2026-72830 | Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-76836 | AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group Bypass | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-78416 | Authenticated RCE via condition.config JSON cleanse bypass | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-56703 | Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTO | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390501 , 393655 |
| CVE-2026-71906 | DrayTek VigorAP Multiple Models OS Command Injection via setLan | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71907 | DrayTek VigorAP Multiple Models OS Command Injection via setcamset | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71908 | DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_test | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-71913 | DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgi | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-71915 | DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatus | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71918 | DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupAction | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-71919 | DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-71923 | DrayTek VigorSwitch Multiple Models OS Command Injection via auth_set | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71924 | DrayTek VigorSwitch Multiple Models OS Command Injection via getVid | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71925 | DrayTek VigorSwitch Multiple Models OS Command Injection via getDetail | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71926 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevice | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71927 | DrayTek VigorSwitch Multiple Models OS Command Injection via rebDevice | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71928 | DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDevice | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71929 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProto | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71930 | DrayTek VigorSwitch Multiple Models OS Command Injection via setTime | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-71931 | DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-71943 | DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNet | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-76844 | webpack-dev-middleware Path Traversal via Offset Slice on a Non-Slash-Terminated publicPath | 347009 |
| CVE-2026-79659 | Ech0 before 4.7.3 Server-Side Request Forgery via fetchPeerConnectInfo | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-34968 | Adminer before 5.4.3 Arbitrary File Deletion via SQLite Drop | 340007 , 344360 , 390709 |
| CVE-2026-56702 | Adminer before 5.4.3 Unrestricted File Upload via AdminerFileUpload | 351000 |
| CVE-2026-72695 | Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFile | 344360 |
| CVE-2026-34964 | Adminer before 5.5.0 SSRF via PDO DSN Injection | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-71932 | DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-78886 | liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-78202 | itsourcecode Payroll System admin_class.php save_settings unrestricted upload | 351000 |
| CVE-2026-78244 | itsourcecode Real Estate Management System search.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-78245 | itsourcecode Online Pharmacy System User Registration register.php move_uploaded_file unrestricted upload | 351000 |
| CVE-2026-78246 | itsourcecode Online Clinic Management System Admin Login login.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-78247 | SourceCodester Simple Online Food Ordering System ajax.php confirm_order sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122 |
| CVE-2026-78248 | SourceCodester Simple Online Food Ordering System ajax.php save_settings sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122 |
| CVE-2026-34959 | Adminer before 5.5.0 Open Redirect via X-Forwarded-Prefix | 340165 , 344365 |
| CVE-2026-34967 | Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Write | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-76837 | Baserow before 2.3.0 Stored Cross-Site Scripting via Rich Text Mention Display Name | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-78864 | liketrek TREK Journey Entry Update journey.controller.t journeyService.updateEntry sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-71503 | Dolibarr < 24.0.0 Reflected XSS via Extra Fields Administration Template | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-79671 | Ech0 before 4.4.3 SSRF via DNS Resolution Bypass | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-78337 | Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVG | 351000 |
| CVE-2026-79670 | Ech0 before 4.4.3 Stored XSS via SVG Upload | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16434 | Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypass | 340007 , 344360 , 347009 , 390709 , 390719 |
| CVE-2026-66882 | Reflected XSS in AshAuthentication confirmation and magic link interaction forms | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-78656 | itsourcecode Sales and Inventory System cust_del.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-78435 | Faveo Helpdesk Logo SettingsController.php unlink path traversal | 340007 , 344360 , 347009 |