Atomicorp WAF Research Notes
Research Update - 2026-09-05
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-44402 | Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-85614 | OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-52775 | YesWiki Authenticated SQL Injection in ReactionManager | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-79423 | seacms v13.6 Arbitrary Code Execution Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-53758 | Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-85604 | Grav before 2.0.19 Remote Code Execution via sort filter | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-85608 | Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-85610 | OpenPanel before 2.3.0 Remote Code Execution via chart formulas | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-85612 | OpenPanel before 2.3.0 SSRF via favicon and og endpoints | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-85666 | ogx 1.3.1 Server-Side Request Forgery via MCP tool server_url | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-85673 | LLaMA-Factory SSRF Guard Bypass via Redirect and DNS Rebinding | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-85685 | AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skill | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-85691 | MegaParse 0.0.55 Server-Side Request Forgery via POST /v1/url | 337109 , 337110 , 344360 , 398001 , 398021 , 398022 |
| CVE-2026-50553 | Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p) | 340007 , 344360 , 390709 |
| CVE-2026-85613 | OpenPanel Unauthenticated XSS via SVG Favicon Proxy | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-52769 | YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub Signature.keyId | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390719 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-52771 | YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (ApiController::deletePage) | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-19303 | Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing c | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-63464 | Nebula-mesh allows non-admin operators to disable webhook SSRF protection via allow_private | 337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-52770 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswiki | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 341250 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-61686 | SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context prop | 340014 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008 |
| CVE-2022-35499 | In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-53757 | Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE | 344360 |
| CVE-2026-73848 | Emlog: Stored XSS via Tag Name in Article Editor | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-74235 | GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download Handler | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-85609 | Openpanel before 2.3.0 SSRF via Site Checker Endpoint | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022 |
| CVE-2026-85662 | Marqo 2.26.0 Server-Side Request Forgery via Media URLs | 337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-14470 | Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base compone | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-9138 | Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing c | 340007 , 344360 , 390709 |
| CVE-2026-8447 | Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untruste | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-85512 | SourceCodester Class and Exam Timetabling System session.php authorization | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-85516 | code-projects Vehicle Management System busprofile.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-17621 | Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base compone | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-85577 | AVideo userLogin.php Reflected XSS via error parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-85650 | Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channel | 334168 , 337109 , 337110 , 344360 , 390719 , 398001 , 398008 , 398021 , 398022 |
| CVE-2026-85676 | Dub Open Redirect via Unrestricted redir_url Parameter | 344365 |
| CVE-2026-85593 | phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-85600 | Grav Admin before 2.0.21 Stored XSS via username | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148 |
| CVE-2026-85601 | Grav Admin before 2.0.20 Cross-Site Scripting via marked.js | 333140 |
| CVE-2026-85643 | code-projects Online Shopping System adduser.php mysqli_query sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-78849 | Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 Arbitrary Code Execution Vulnerability | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |