Atomicorp WAF Research Notes

Research Update - 2026-08-28

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-34976Dgraph <=v25.3.0 - Admin Mutation Missing Authorization398008
CVE-2026-44182Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering340014 , 344362 , 344363 , 344364 , 344366
CVE-2026-81735UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authentication, Exposing Arbitrary Command Executi340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-34838Group-Office: Authenticated Remote Code Execution via PHP Insecure Deserialization in AbstractSettingsCollection340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2017-18349Fastjson Insecure Deserialization - Remote Code Execution344380 , 344385 , 398008
CVE-2020-9547FasterXML jackson-databind - Deserialization Remote Code Execution398008
CVE-2020-9548FasterXML Jackson Databind <=2.9.10.4 - Remote Code Execution398008
CVE-2023-1177Mlflow <2.2.1 - Local File Inclusion398008
CVE-2023-2780Mlflow <2.3.1 - Local File Inclusion Bypass398008
CVE-2024-22319IBM Operational Decision Manager - JNDI Injection398008
CVE-2024-5932GiveWP - PHP Object Injection398001
CVE-2026-18482neo-mjs Command Injection Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-19912Kaltura HTML5 Video Player, html5 library Arbitrary Code Execution Vulnerability340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-75330super-diamond-server <= 1.3.3 is vulnerable to SQL injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-75336Funiture 1.0.0 SQL Injection Vulnerability340145 , 380122
CVE-2026-81672Multiple Vulnerabilities in TOOOLS' iSquad340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-81673Multiple Vulnerabilities in TOOOLS' iSquad340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-81674Multiple Vulnerabilities in TOOOLS' iSquad340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-81675Multiple Vulnerabilities in TOOOLS' iSquad340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-10042manga-image-translator RCE via Unsafe Pickle Deserialization in Share Model340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-42281MagicMirror <= 2.35.0 - Server-Side Request Forgery398001
CVE-2026-57499Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE)340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-75332Zyplayer-Doc <=1.0.0 Server-Side Request Forgery Vulnerability337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-14602Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-32475Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form Handler398001
CVE-2025-68613n8n - Remote Code Execution via Expression Injection340130 , 344361 , 344363 , 344364 , 345240 , 380026
CVE-2026-26899OS Command Injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-81676Multiple Vulnerabilities in TOOOLS' iSquad340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-81677Multiple Vulnerabilities in TOOOLS' iSquad340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-81730Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filename340007 , 344360 , 390709
CVE-2025-71260BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-47722nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml340014 , 340023 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008
CVE-2026-76060OS Command Injection in PayRange API340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-81093Apify Actors MCP Server before 0.9.12 Server-Side Request Forgery via get-html-skeleton340162 , 340165 , 347009 , 390722
CVE-2026-81728Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keys340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-69101Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint330791 , 340152 , 344360 , 344370 , 344372 , 344373 , 398008
CVE-2025-2563User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalation300020
CVE-2026-53580Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download feature340007 , 347009
CVE-2026-54083Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletion340007 , 344360 , 390709
CVE-2026-12720Kirki < 6.0.13 - Unauthenticated PHP Object Injection340014 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008
CVE-2026-19913Kaltura HTML5 Video Player, html5lib library Improper Input Validation Vulnerability340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-2614MLflow <= 3.9.0 - Arbitrary File Read398008
CVE-2026-36851UnPoller 2.33.0 password field Path Traversal Vulnerability340007 , 344360 , 390709
CVE-2026-75328In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java Path Traversal Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-75333yx-image-recognition v1.0 Path Traversal Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-40526Volmarg Personal Management System Path Traversal via get-file Endpoint340007 , 344360 , 347009 , 390709
CVE-2025-71257BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-81678AVideo SSRF Guard Bypass via IPv6 Transition Addresses337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-48710Starlette - Improper Validation of Unsafe Equivalence in Input320009
CVE-2026-82081wallabag Server-Side Request Forgery Vulnerability337109 , 337110 , 344360 , 398021 , 398022
CVE-2022-30983Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 Cross-Site Scripting Vulnerability333140 , 333141 , 340147 , 340148 , 341256 , 346755
CVE-2024-25608Liferay Portal - Open Redirect398005
CVE-2026-79653Eclipse SW360 Path Traversal Vulnerability340007 , 344360 , 390709
CVE-2022-3590WordPress <= 6.2 - Server Side Request Forgery398001
CVE-2026-81931Unrestricted upload of file with dangerous type in Prospero Flow CRM product photo allows stored cross-site scripting351000
CVE-2026-75331tamguo 1.5.3 Cross-Site Scripting Vulnerability333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-16297Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import340014 , 340023 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390904 , 398008
CVE-2026-81845arben-adm mcp-sequential-thinking Import Session/Export Session server.py export_session path traversal340007 , 344360 , 390709
CVE-2026-81835RooCodeInc Roo-Code MCP Integration Trust Model malicious_mcp_server.py fetch_instructions code injection340014 , 344360 , 347009 , 393655
CVE-2026-81847MAA-AI MaaMCP pipeline_tools.py load_pipeline path traversal340007 , 344360 , 390709