Atomicorp WAF Research Notes
Research Update - 2026-09-03
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-49869 | Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in AuthenticationFilter | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2025-9314 | Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload | 351000 |
| CVE-2026-75327 | In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java Arbitrary File Upload Vulnerability | 351000 |
| CVE-2026-75411 | JeecgBoot v3.9.2 Code Injection Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-75414 | In AntFlow V2.0.0, ActivitiTest.java Code Injection Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-79408 | MetaGPT 0.8.1 Command Injection Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-84372 | Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390722 , 393655 |
| CVE-2026-53649 | Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2023-7305 | SmartBI RMIServlet Unrestricted File Upload RCE | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-84189 | LibreNMS before 26.7.0 Stored XSS via Oxidized API | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-71981 | Cypht < 2.12.2 PHP Object Injection RCE via back_query Parameter | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2026-79756 | Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platform | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-84208 | AVideo User_Location Plugin Unauthenticated SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82524 | UnoPim File Upload RCE via TinyMCE Image Upload Endpoint | 351000 |
| CVE-2026-84194 | LibreNMS 23.10.0 before 26.4.0 OS Command Injection via Hostname | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-84803 | SiYuan before v3.8.2 Stored XSS via incomplete asset blocklist | 333140 , 333141 |
| CVE-2026-52831 | Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 390719 |
| CVE-2026-79755 | Nuclio: Unauthenticated OS command injection via function namespace in docker ps –filter label (local Docker platform) | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-79407 | the SPO extension of MetaGPT 0.8.1 Path Traversal Vulnerability | 340007 , 344360 |
| CVE-2026-19914 | Welcart e-Commerce <= 2.12.1 - Unauthenticated Stored Cross-Site Scripting via 'custom_order' Parameter | 333140 , 340095 , 340147 , 341256 , 342259 , 346755 |
| CVE-2026-84192 | LibreNMS before 26.3.1 Stored XSS via SNMP/Syslog Data | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148 |
| CVE-2026-84199 | Kyverno before 1.16.2 SSRF via APICall Feature | 337109 , 337110 , 344360 , 398001 , 398021 , 398022 |
| CVE-2026-8712 | Wyoming < 1.10.2 SSRF via uri Query Parameter | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-55421 | Open edX Platform: SSRF in Studio Video Download Endpoint | 337109 , 337110 , 344360 , 398001 , 398021 , 398022 |
| CVE-2026-10821 | Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 360029 , 390904 |
| CVE-2025-63607 | TechStore 1.0 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-84193 | LibreNMS through 26.2.0 Stored Cross-Site Scripting via SNMP | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-13786 | taosir WTCMS index.php fetch code injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390768 , 393655 |
| CVE-2025-13792 | Qualitor getResumo.php eval code injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2025-13810 | jsnjfz WebStack-Guns KaptchaController.java renderPicture path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2025-13814 | moxi159753 Mogu Blog v2 uploadPicsByUrl LocalFileServiceImpl.uploadPictureByUrl server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-84111 | Chanjet CRM jxf_dump_table.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-84441 | Piwigo Image Derivative i.php path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2023-7299 | DataGear resolveSql sql injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-84175 | Eclipse Ditto Uncontrolled Recursion Vulnerability | 337109 , 337110 , 344360 , 398001 , 398021 , 398022 |
| CVE-2026-84191 | LibreNMS before 26.5.0 Stored XSS via SNMP VRF fields | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-84207 | Heym before 0.0.98 SSRF via WebSocket endpoints | 337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-84477 | AVideo Stored XSS via Live Schedule Title Description | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-52832 | Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dashboard container | 340007 , 344360 , 390709 |
| CVE-2026-84188 | librenms before 26.7.0 Stored XSS via graph_descr settings | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-53683 | Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html | 340163 , 344365 |
| CVE-2023-3360 | Weaver Show Posts < 1.8.1 - Admin+ PHP Object Injection | 340014 , 340023 , 344362 , 344363 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008 |
| CVE-2025-13789 | ZenTao model.php makeRequest server-side request forgery | 337109 , 337110 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2025-13809 | orionsec orion-ops SSH Connection MachineInfoController.java server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2025-13811 | jsnjfz WebStack-Guns PageFactory.java sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-13815 | moxi159753 Mogu Blog v2 pictures unrestricted upload | 351000 |
| CVE-2025-13816 | moxi159753 Mogu Blog v2 ZIP File unzipFile FileOperation.unzip path traversal | 340007 , 344360 , 390709 |
| CVE-2025-13875 | Yohann0617 oci-helper OCI Configuration Upload OciServiceImpl.java addCfg path traversal | 340007 , 344360 , 390709 |
| CVE-2026-84109 | Xinhu Rainrock RockOA webmainAction.php getOrder sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-84153 | Xinhu Rainrock RockOA index.php toaddval sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-84437 | OpenCart Autocomplete Workflow address.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 340247 , 340248 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-84438 | OpenCart Autocomplete Workflow edit.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |