Atomicorp WAF Research Notes
Research Update - 2026-09-01
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-59111 | Command Injection vulnerability in eObčanka-Identifikace | 340014 , 347009 , 393655 |
| CVE-2026-51152 | Server-Side Request Forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-82217 | Eclipse Theia Path Traversal Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-81889 | elFinder: SSRF protection bypass via DNS rebinding in the fsock_get_contents() fallback | 337109 , 337110 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-82692 | D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-22244 | OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCE | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-61640 | Wallos: SSRF via OIDC Token/UserInfo URL Configuration | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-82690 | D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-82691 | D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-61638 | Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-77348 | Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.ph | 337109 , 337110 , 340790 , 340791 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-53553 | Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise | 340007 , 344360 , 390709 |
| CVE-2026-79749 | MCPHub: SSRF Guard Bypass via IPv6 Transition Addresses in URL Validation | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-75132 | WAPT Server SQL Injection via /api/v3/hosts Endpoint | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-79747 | MCPHub vulnerable to SSRF: a non-admin user can make mcphub request arbitrary URLs and read the response (OpenAPI proxy | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-82877 | ILIAS before 9.22 Arbitrary File Read via SOAP addFile | 340007 , 344360 , 390709 |
| CVE-2026-75592 | Kirby: Access to image files outside of the site root via path traversal in the media handling | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-79743 | MCPHub: Path Traversal via Malicious MCPB Manifest Name | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-82630 | PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-82701 | code-projects Online Shopping System Search Functionality action.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82801 | NASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgery | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-82802 | NASA earthdata-search granules Endpoint handler.js OpenSearchGranuleSearchLambda server-side request forgery | 337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-82396 | Sulu: Stored XSS via media download inline-disposition override | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-77352 | Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user) | 337109 , 337110 , 344360 , 398001 , 398021 , 398022 |
| CVE-2026-77351 | Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-82625 | code-projects Simple Inventory System User Registration register.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-82664 | yaojingang GEOFlow JSON-LD Theme HomeController.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-82679 | diem-project diem Widget Editor dmWidgetContentBaseMediaForm.php unrestricted upload | 351000 |
| CVE-2026-82696 | itsourcecode Sales and Inventory System inv_searchfrm.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82700 | code-projects Online Shopping System Newsletter Subscription offersmail.php cross site scripting | 333140 , 333141 , 340147 , 340148 , 341256 , 346755 |
| CVE-2026-82905 | sdcb chats fetch-tools Endpoint McpController.cs McpController server-side request forgery | 337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-83744 | invoiceninja Invoice Ninja invoices Endpoint Purify.php isHostSafe server-side request forgery | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-82622 | code-projects Employee Leave Managing System Employee Profile Update editaction.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-82629 | jeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwid3Controller.doUpload unrestricted upload | 351000 |
| CVE-2026-82665 | yaojingang GEOFlow Image Library Cleanup ImageLibraryController.php unlink path traversal | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-82666 | yaojingang GEOFlow Superadmin Theme Editor SiteThemeEditorController.php preview code injection | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-82667 | yaojingang GEOFlow GenericHttpEndpointResolver.php DistributionController.isValidHttpEndpoint server-side request forger | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-82678 | diem-project diem Administrative Console actions.class.php executeCommand os command injection | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 |
| CVE-2026-82702 | Edimax BR-6214K asp_WlanMP Endpoint wlanMP.asp system os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-82703 | Edimax BR-6214K asp_setPing Endpoint ping.asp system os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |