Atomicorp WAF Research Notes

Research Update - 2026-09-05

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-44402Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-85614OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-52775YesWiki Authenticated SQL Injection in ReactionManager340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-79423seacms v13.6 Arbitrary Code Execution Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-53758Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-85604Grav before 2.0.19 Remote Code Execution via sort filter340014 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-85608Douyin_TikTok_Download_API 4.1.2 SSRF via url parameter337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-85610OpenPanel before 2.3.0 Remote Code Execution via chart formulas340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-85612OpenPanel before 2.3.0 SSRF via favicon and og endpoints337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-85666ogx 1.3.1 Server-Side Request Forgery via MCP tool server_url337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-85673LLaMA-Factory SSRF Guard Bypass via Redirect and DNS Rebinding337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-85685AgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skill340007 , 344360 , 347009 , 390709
CVE-2026-85691MegaParse 0.0.55 Server-Side Request Forgery via POST /v1/url337109 , 337110 , 344360 , 398001 , 398021 , 398022
CVE-2026-50553Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)340007 , 344360 , 390709
CVE-2026-85613OpenPanel Unauthenticated XSS via SVG Favicon Proxy333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-52769YesWiki: Unauthenticated Server-Side Request Forgery via ActivityPub Signature.keyId337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390719 , 390722 , 398001 , 398021 , 398022
CVE-2026-52771YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (ApiController::deletePage)340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-19303Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing c340007 , 344360 , 347009 , 390709
CVE-2026-63464Nebula-mesh allows non-admin operators to disable webhook SSRF protection via allow_private337109 , 337110 , 340162 , 340163 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-52770Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in yeswiki/yeswiki340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 341250 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-61686SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context prop340014 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 , 398008
CVE-2022-35499In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-53757Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE344360
CVE-2026-73848Emlog: Stored XSS via Tag Name in Article Editor333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-74235GFI Exinda AI / ClearView < 7.6.5 Path Traversal via Configuration Download Handler340007 , 344360 , 347009 , 390709
CVE-2026-85609Openpanel before 2.3.0 SSRF via Site Checker Endpoint337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398001 , 398021 , 398022
CVE-2026-85662Marqo 2.26.0 Server-Side Request Forgery via Media URLs337109 , 337110 , 344360 , 398001 , 398008 , 398021 , 398022
CVE-2026-14470Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base compone340007 , 344360 , 347009 , 390709
CVE-2026-9138Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing c340007 , 344360 , 390709
CVE-2026-8447Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering and untruste333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-85512SourceCodester Class and Exam Timetabling System session.php authorization340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85516code-projects Vehicle Management System busprofile.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-17621Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base compone340007 , 344360 , 347009 , 390709
CVE-2026-85577AVideo userLogin.php Reflected XSS via error parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-85650Trigger.dev before 4.5.2 Server-Side Request Forgery via webhook alert-channel334168 , 337109 , 337110 , 344360 , 390719 , 398001 , 398008 , 398021 , 398022
CVE-2026-85676Dub Open Redirect via Unrestricted redir_url Parameter344365
CVE-2026-85593phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-85600Grav Admin before 2.0.21 Stored XSS via username333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2026-85601Grav Admin before 2.0.20 Cross-Site Scripting via marked.js333140
CVE-2026-85643code-projects Online Shopping System adduser.php mysqli_query sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78849Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 Arbitrary Code Execution Vulnerability333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148