Atomicorp WAF Research Notes
Research Update - 2026-08-27
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-58192 | Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-plugin | 340007 , 344360 |
| CVE-2026-68000 | MCMS <=6.2.0 is vulnerable to SQL injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-77806 | SPIP < 4.4.22 - Unauthenticated RCE | 380018 , 380026 |
| CVE-2020-15874 | Command Injection | 340014 , 340023 , 340029 , 340193 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2020-15876 | SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2020-15878 | SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-56798 | Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier Cross-Site Request Forgery Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 , 393655 |
| CVE-2026-7467 | Read More & Accordion <= 3.5.7 - Authenticated Privilege Escalation | 377360 |
| CVE-2026-47665 | Penpot: Stored XSS via comment content, innerHTML renders unsanitized HTML | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-55182 | LibreNMS: Remote Code Execution by Signal Alert Transportation Module | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-5917 | libgit2 Shell Command Injection via ssh_libssh2 Backend | 340014 , 347009 , 393655 |
| CVE-2026-80214 | LibreNMS Virtualisation Discovery Module RCE | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-81029 | OpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redirect URI | 344365 |
| CVE-2026-81036 | Stalwart Mail Server through 0.16.19 Authorization Code Disclosure via Unvalidated OAuth redirect_uri | 344365 |
| CVE-2026-15973 | LimeSurvey 7.0.5 - Stored XSS in Survey Menu Entries | 333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16809 | LimeSurvey Community Edition 7.0.5 - Stored XSS in quota message rendering | 333140 , 333141 , 340147 , 340148 , 341256 , 346755 |
| CVE-2026-80350 | OneUptime before 12.0.7 Server-Side Request Forgery via IPv4-Mapped IPv6 Webhook URL | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-81030 | Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_items Endpoint | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-80426 | FiftyOne before 1.21.0 Stored Cross-Site Scripting via Unescaped Field Description | 333140 , 333141 |
| CVE-2026-39275 | Cockpit CMS v.2.13.5 and before Arbitrary Code Execution Vulnerability | 340099 , 341099 |
| CVE-2026-81203 | SourceCodester Simple Online Food Ordering System ajax.php login2 sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122 |
| CVE-2026-81421 | ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-81486 | bsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversal | 340007 , 344360 , 390709 |
| CVE-2026-81491 | boxpositron with-context-mcp index.ts project_folder path traversal | 340007 , 344360 , 390709 |
| CVE-2026-45694 | LibreNMS: Reflected XSS in the Proxmox app view via unsanitized instance/vmid parameters | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-80200 | Kimai before 2.53.0 Open Redirect via RelayState | 344365 |
| CVE-2026-65930 | LimeSurvey Community Edition 7.0.5 - Stored XSS in replacement-fields | 333140 , 333141 , 340095 , 342259 |