Atomicorp WAF Research Notes
Research Update - 2026-08-28
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-34976 | Dgraph <=v25.3.0 - Admin Mutation Missing Authorization | 398008 |
| CVE-2026-44182 | Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering | 340014 , 344362 , 344363 , 344364 , 344366 |
| CVE-2026-81735 | UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command Executi | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-34838 | Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in AbstractSettingsCollection | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2017-18349 | Fastjson Insecure Deserialization - Remote Code Execution | 344380 , 344385 , 398008 |
| CVE-2020-9547 | FasterXML jackson-databind - Deserialization Remote Code Execution | 398008 |
| CVE-2020-9548 | FasterXML Jackson Databind <=2.9.10.4 - Remote Code Execution | 398008 |
| CVE-2023-1177 | Mlflow <2.2.1 - Local File Inclusion | 398008 |
| CVE-2023-2780 | Mlflow <2.3.1 - Local File Inclusion Bypass | 398008 |
| CVE-2024-22319 | IBM Operational Decision Manager - JNDI Injection | 398008 |
| CVE-2024-5932 | GiveWP - PHP Object Injection | 398001 |
| CVE-2026-18482 | neo-mjs Command Injection Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-19912 | Kaltura HTML5 Video Player, html5 library Arbitrary Code Execution Vulnerability | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2026-75330 | super-diamond-server <= 1.3.3 is vulnerable to SQL injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-75336 | Funiture 1.0.0 SQL Injection Vulnerability | 340145 , 380122 |
| CVE-2026-81672 | Multiple Vulnerabilities in TOOOLS' iSquad | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-81673 | Multiple Vulnerabilities in TOOOLS' iSquad | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-81674 | Multiple Vulnerabilities in TOOOLS' iSquad | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-81675 | Multiple Vulnerabilities in TOOOLS' iSquad | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-10042 | manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2026-42281 | MagicMirror <= 2.35.0 - Server-Side Request Forgery | 398001 |
| CVE-2026-57499 | Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE) | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-75332 | Zyplayer-Doc <=1.0.0 Server-Side Request Forgery Vulnerability | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-14602 | Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2026-32475 | Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form Handler | 398001 |
| CVE-2025-68613 | n8n - Remote Code Execution via Expression Injection | 340130 , 344361 , 344363 , 344364 , 345240 , 380026 |
| CVE-2026-26899 | OS Command Injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-81676 | Multiple Vulnerabilities in TOOOLS' iSquad | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-81677 | Multiple Vulnerabilities in TOOOLS' iSquad | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-81730 | Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filename | 340007 , 344360 , 390709 |
| CVE-2025-71260 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2026-47722 | nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml | 340014 , 340023 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008 |
| CVE-2026-76060 | OS Command Injection in PayRange API | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-81093 | Apify Actors MCP Server before 0.9.12 Server-Side Request Forgery via get-html-skeleton | 340162 , 340165 , 347009 , 390722 |
| CVE-2026-81728 | Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keys | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-69101 | Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint | 330791 , 340152 , 344360 , 344370 , 344372 , 344373 , 398008 |
| CVE-2025-2563 | User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalation | 300020 |
| CVE-2026-53580 | Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download feature | 340007 , 347009 |
| CVE-2026-54083 | Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletion | 340007 , 344360 , 390709 |
| CVE-2026-12720 | Kirki < 6.0.13 - Unauthenticated PHP Object Injection | 340014 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008 |
| CVE-2026-19913 | Kaltura HTML5 Video Player, html5lib library Improper Input Validation Vulnerability | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2026-2614 | MLflow <= 3.9.0 - Arbitrary File Read | 398008 |
| CVE-2026-36851 | UnPoller 2.33.0 password field Path Traversal Vulnerability | 340007 , 344360 , 390709 |
| CVE-2026-75328 | In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java Path Traversal Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-75333 | yx-image-recognition v1.0 Path Traversal Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-40526 | Volmarg Personal Management System Path Traversal via get-file Endpoint | 340007 , 344360 , 347009 , 390709 |
| CVE-2025-71257 | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2026-81678 | AVideo SSRF Guard Bypass via IPv6 Transition Addresses | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-48710 | Starlette - Improper Validation of Unsafe Equivalence in Input | 320009 |
| CVE-2026-82081 | wallabag Server-Side Request Forgery Vulnerability | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2022-30983 | Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340147 , 340148 , 341256 , 346755 |
| CVE-2024-25608 | Liferay Portal - Open Redirect | 398005 |
| CVE-2026-79653 | Eclipse SW360 Path Traversal Vulnerability | 340007 , 344360 , 390709 |
| CVE-2022-3590 | WordPress <= 6.2 - Server Side Request Forgery | 398001 |
| CVE-2026-81931 | Unrestricted upload of file with dangerous type in Prospero Flow CRM product photo allows stored cross-site scripting | 351000 |
| CVE-2026-75331 | tamguo 1.5.3 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-16297 | Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import | 340014 , 340023 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390904 , 398008 |
| CVE-2026-81845 | arben-adm mcp-sequential-thinking Import Session/Export Session server.py export_session path traversal | 340007 , 344360 , 390709 |
| CVE-2026-81835 | RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions code injection | 340014 , 344360 , 347009 , 393655 |
| CVE-2026-81847 | MAA-AI MaaMCP pipeline_tools.py load_pipeline path traversal | 340007 , 344360 , 390709 |