Atomicorp WAF Research Notes

Research Update - 2026-09-04

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-82526R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-58400GeoNetwork vulnerable to Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-82866@pdfme/common before 5.5.10 SSRF via Unvalidated URL Fetch337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-85199Eclipse aeriOS Path Traversal Vulnerability340007 , 344360 , 390709
CVE-2026-82527R2R 3.6.6 SQL Injection via Retrieval Search Filter Key340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341250 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85155WWBN AVideo SQL Injection via get.json.php APIName channels340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85223D-Link DNS-340L CGI dropbox.cgi os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-85222D-Link DNS-340L Add-On Center addon_center.cgi os command injection340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-85224D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-85160AVideo through c91b5975d CSRF and Path Traversal via stopLive.php340007 , 344360 , 347009 , 390709
CVE-2026-53728Medplum - Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage340162 , 340163 , 344365
CVE-2026-85163AVideo Server-Side Request Forgery via epg_link parameter337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-85164WWBN AVideo Server-Side Request Forgery via set_api_userImages337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-75602OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool340007 , 344360 , 390709
CVE-2026-85137SeaCMS Locoy Collector seacms_locoy_news.php parseIf code injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-85138SeaCMS WeChat index.php addslashes sql injection340156
CVE-2026-85187itsourcecode Online Medicine Delivery System Order Status Update controller.php pupdate sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85208itsourcecode Online Medicine Delivery System Order Management Controller controller.php doInsert unrestricted upload351000
CVE-2026-85225code-projects Doctor Appointment System patient_login.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85379light0011 cms Query Builder ChapterController.class.php searchChapter sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85380light0011 cms UEditor controller.php catchimage server-side request forgery337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398001 , 398008 , 398021 , 398022
CVE-2026-85397code-projects Hospital Information System addReq.php findBySearch sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85398code-projects Hospital Information System viewReq.php viewReq sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85399code-projects Hospital Information System PrespController.php getSinglePresp sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85402code-projects Doctor Appointment System booking.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85403code-projects Doctor Appointment System contactus.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85158AVideo Reflected XSS via videoEmbeded.php link parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-85159AVideo Reflected XSS via cancelUri in userLogin.php333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-85205itsourcecode Online Medicine Delivery System Wishlist controller.php addwishlist sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-56126pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via status_monitoring.php333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-56127pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_rules_edit.php333140 , 333141 , 342259
CVE-2026-56128pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_schedule_edit.php333140 , 333141 , 342259
CVE-2024-7631Openshift-console: openshift console: path traversal340007 , 344360 , 347009 , 390709
CVE-2026-85021langgenius dify Splash Layout splash.tsx router.replace cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-85186itsourcecode Online Medicine Delivery System Customer Controller controller.php doupdateimage unrestricted upload351000
CVE-2026-85382light0011 cms Chapter Content Output oneChapter.tpl htmlspecialchars_decode cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-85383itsourcecode Sales and Inventory System inv_del.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85022langgenius dify WebApp Sign-In mail-and-password-auth.tsx router.replace cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-85040ZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-85207itsourcecode Online Medicine Delivery System index.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148