Atomicorp WAF Research Notes

Research Update - 2026-08-27

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-58192Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-plugin340007 , 344360
CVE-2026-68000MCMS <=6.2.0 is vulnerable to SQL injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-77806SPIP < 4.4.22 - Unauthenticated RCE380018 , 380026
CVE-2020-15874Command Injection340014 , 340023 , 340029 , 340193 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2020-15876SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2020-15878SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-56798Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier Cross-Site Request Forgery Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 393655
CVE-2026-7467Read More & Accordion <= 3.5.7 - Authenticated Privilege Escalation377360
CVE-2026-47665Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-55182LibreNMS: Remote Code Execution by Signal Alert Transportation Module340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-5917libgit2 Shell Command Injection via ssh_libssh2 Backend340014 , 347009 , 393655
CVE-2026-80214LibreNMS Virtualisation Discovery Module RCE340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-81029OpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redirect URI344365
CVE-2026-81036Stalwart Mail Server through 0.16.19 Authorization Code Disclosure via Unvalidated OAuth redirect_uri344365
CVE-2026-15973LimeSurvey 7.0.5 - Stored XSS in Survey Menu Entries333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148
CVE-2026-16809LimeSurvey Community Edition 7.0.5 - Stored XSS in quota message rendering333140 , 333141 , 340147 , 340148 , 341256 , 346755
CVE-2026-80350OneUptime before 12.0.7 Server-Side Request Forgery via IPv4-Mapped IPv6 Webhook URL337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-81030Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items Endpoint340007 , 344360 , 347009 , 390709
CVE-2026-80426FiftyOne before 1.21.0 Stored Cross-Site Scripting via Unescaped Field Description333140 , 333141
CVE-2026-39275Cockpit CMS v.2.13.5 and before Arbitrary Code Execution Vulnerability340099 , 341099
CVE-2026-81203SourceCodester Simple Online Food Ordering System ajax.php login2 sql injection340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122
CVE-2026-81421ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-81486bsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversal340007 , 344360 , 390709
CVE-2026-81491boxpositron with-context-mcp index.ts project_folder path traversal340007 , 344360 , 390709
CVE-2026-45694LibreNMS: Reflected XSS in the Proxmox app view via unsanitized instance/vmid parameters333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-80200Kimai before 2.53.0 Open Redirect via RelayState344365
CVE-2026-65930LimeSurvey Community Edition 7.0.5 - Stored XSS in replacement-fields333140 , 333141 , 340095 , 342259