Atomicorp WAF Research Notes
Research Update - 2026-09-09
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2025-67066 | oasys sysoa version 1.0 Arbitrary Code Execution Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-70149 | membership management system SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-70150 | membership management system Missing Authorization Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-70152 | scholars tracking system SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-79569 | Movie_Recommend v1.0.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86738 | Snipe-IT before 8.7.0 CSS Injection via Custom CSS | 333140 , 340095 , 342259 |
| CVE-2026-53581 | ntp: write path traversal | 340007 , 344360 , 390709 |
| CVE-2025-70151 | scholars tracking system Arbitrary Code Execution Vulnerability | 351000 |
| CVE-2026-86542 | knowns before 0.30.0 Path Traversal via Import Name | 340007 , 344360 , 390709 |
| CVE-2025-34115 | OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.php | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-86538 | knowns before 0.30.0 Path Traversal via templateFile parameter | 344360 , 390709 |
| CVE-2026-86732 | Craft CMS before 5.10.12 Remote Code Execution via element-index | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-61517 | Netis NX10 OS Command Injection via Ping Diagnostic Handler | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-86299 | Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-86437 | Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-86438 | Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-86733 | Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-58113 | Teamcenter V2412 Cross-site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86207 | N-able N-central - Authentication Bypass | 344365 |
| CVE-2026-86206 | N-able N-central - Access Control Bypass via Path Confusion and Forwarded Header Spoofing | 344365 |
| CVE-2026-86539 | knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-86806 | opengeos GeoLibre _is_within_roots server-side request forgery | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 350591 , 390722 , 398021 , 398022 |
| CVE-2026-78838 | AppNitro MachForm v30 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86590 | Eclipse Che Server-Side Request Forgery Vulnerability | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-86735 | snipe-it before 8.7.0 SSRF via IPv6 transition address bypass | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-54611 | InstantCMS has Remote Code Execution in package installer | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-86290 | SourceCodester Online Voting System ajax.php save_category sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122 |
| CVE-2026-86298 | SourceCodester Class and Exam Timetabling System delete_subject.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86305 | light0011 cms Upload.class.php upload unrestricted upload | 351000 |
| CVE-2026-86666 | aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload | 351000 |
| CVE-2026-73319 | XenForo < 2.3.13 XSS via Dynamic Redirect Handler | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-48707 | InstantCMS vulnerable to SSRF via upload redirect bypass allows internal network service scanning | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-86291 | itsourcecode Sales and Inventory System us_edit1.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86294 | SourceCodester Simple Traffic Offense System Settings Update Endpoint save-settings.php cross site scripting | 333140 , 333141 , 340095 , 342259 |
| CVE-2026-86309 | itsourcecode Sales and Inventory System pro_searchfrm.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86310 | itsourcecode Sales and Inventory System cust_edit1.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86517 | itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86518 | code-projects Student Crud Operation edit.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86668 | aircheng-org iWebShop-5 pic.php uploadFile cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86675 | itsourcecode Sales and Inventory System us_edit.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86301 | code-projects Hospital Information System Patient Management editPatient.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86644 | star7th showdoc API Page Save Endpoint editormd.js cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86667 | aircheng-org iWebShop-5 member.php member_list sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |