Atomicorp WAF Research Notes
Research Update - 2026-09-04
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-82526 | R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-58400 | GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-82866 | @pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-85199 | Eclipse aeriOS Path Traversal Vulnerability | 340007 , 344360 , 390709 |
| CVE-2026-82527 | R2R 3.6.6 SQL Injection via Retrieval Search Filter Key | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341250 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-85155 | WWBN AVideo SQL Injection via get.json.php APIName channels | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-85223 | D-Link DNS-340L CGI dropbox.cgi os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-85222 | D-Link DNS-340L Add-On Center addon_center.cgi os command injection | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-85224 | D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-85160 | AVideo through c91b5975d CSRF and Path Traversal via stopLive.php | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-53728 | Medplum - Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage | 340162 , 340163 , 344365 |
| CVE-2026-85163 | AVideo Server-Side Request Forgery via epg_link parameter | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-85164 | WWBN AVideo Server-Side Request Forgery via set_api_userImages | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-75602 | OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool | 340007 , 344360 , 390709 |
| CVE-2026-85137 | SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-85138 | SeaCMS WeChat index.php addslashes sql injection | 340156 |
| CVE-2026-85187 | itsourcecode Online Medicine Delivery System Order Status Update controller.php pupdate sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-85208 | itsourcecode Online Medicine Delivery System Order Management Controller controller.php doInsert unrestricted upload | 351000 |
| CVE-2026-85225 | code-projects Doctor Appointment System patient_login.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-85379 | light0011 cms Query Builder ChapterController.class.php searchChapter sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-85380 | light0011 cms UEditor controller.php catchimage server-side request forgery | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-85397 | code-projects Hospital Information System addReq.php findBySearch sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-85398 | code-projects Hospital Information System viewReq.php viewReq sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-85399 | code-projects Hospital Information System PrespController.php getSinglePresp sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-85402 | code-projects Doctor Appointment System booking.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-85403 | code-projects Doctor Appointment System contactus.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-85158 | AVideo Reflected XSS via videoEmbeded.php link parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-85159 | AVideo Reflected XSS via cancelUri in userLogin.php | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-85205 | itsourcecode Online Medicine Delivery System Wishlist controller.php addwishlist sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-56126 | pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via status_monitoring.php | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-56127 | pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_rules_edit.php | 333140 , 333141 , 342259 |
| CVE-2026-56128 | pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_schedule_edit.php | 333140 , 333141 , 342259 |
| CVE-2024-7631 | Openshift-console: openshift console: path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-85021 | langgenius dify Splash Layout splash.tsx router.replace cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-85186 | itsourcecode Online Medicine Delivery System Customer Controller controller.php doupdateimage unrestricted upload | 351000 |
| CVE-2026-85382 | light0011 cms Chapter Content Output oneChapter.tpl htmlspecialchars_decode cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-85383 | itsourcecode Sales and Inventory System inv_del.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-85022 | langgenius dify WebApp Sign-In mail-and-password-auth.tsx router.replace cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-85040 | ZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-85207 | itsourcecode Online Medicine Delivery System index.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |