Atomicorp WAF Research Notes
Research Update - 2026-09-07
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-86259 | OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation | 337109 , 337110 , 340162 , 340163 , 344360 , 390719 , 398021 , 398022 |
| CVE-2026-0561 | Shield Security <= 21.0.8 - Unauthenticated Reflected XSS | 340147 , 340148 , 341266 , 346755 |
| CVE-2026-86180 | code-projects Task Management System In PHP Login index.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86208 | SourceCodester Class and Exam Timetabling System delete_teacher.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86209 | SourceCodester Class and Exam Timetabling System delete_user.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86210 | SourceCodester Class and Exam Timetabling System delete_user_account.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86211 | rabindralamsal inventory-management-system Login index.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86213 | Mstfakts College-Management-System Search university.php mysqli_query sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86220 | SourceCodester Class and Exam Timetabling System modal_add_course.php mysqli_query sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86221 | SourceCodester Class and Exam Timetabling System modal_add_course1.php mysqli_query sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86222 | SourceCodester Class and Exam Timetabling System modal_add_course2.php mysqli_query sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86223 | SourceCodester Class and Exam Timetabling System modal_add_coursea.php mysqli_query sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86224 | SourceCodester Class and Exam Timetabling System modal_add_product.php mysqli_query sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86225 | SourceCodester Class and Exam Timetabling System modal_add_room.php mysqli_query sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86237 | openagents-org openagents http.py test_default_model server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-86239 | liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload | 351000 |
| CVE-2026-86268 | itsourcecode School Management System User_Login.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86273 | projeto-siga HTML-to-PDF Endpoint ExUtilController.java DownloadExterno.getUrl server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-86205 | h3 before 2.0.1-rc.18 Open Redirect via redirectBack() | 344365 |
| CVE-2026-86256 | wger before 2.6 Open Redirect via trainer-login next parameter | 344365 |
| CVE-2026-86171 | DefaultFuction CRM delete.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86172 | DefaultFuction CRM delete.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86216 | code-projects Hotel and Tourism Reservation in PHP details.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86232 | itsourcecode Sales and Inventory System sup_del.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86233 | itsourcecode Sales and Inventory System us_del.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86234 | itsourcecode Sales and Inventory System cust_transac.php add sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86235 | itsourcecode Sales and Inventory System pos_transac.php add sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86236 | itsourcecode Sales and Inventory System pro_transac.php add sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86244 | FastAdmin User Controller User.php login cross site scripting | 333140 , 333141 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86245 | itsourcecode Sales and Inventory System sup_transac.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86265 | itsourcecode Sales and Inventory System us_transac.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86267 | itsourcecode Information System Society Membership System check_student.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86269 | itsourcecode Sales and Inventory System emp_edit1.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86270 | itsourcecode Sales and Inventory System settings_edit.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86278 | SourceCodester Syllabus-Aligned Learning Management & Examination System manage_subjects.php cross site scripting | 333140 , 333141 , 340087 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-86181 | code-projects Task Management System User Profile Update UpdateUserProfile.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86240 | liufee FeehiCMS UEditor Uploader.php catchImage server-side request forgery | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |