Atomicorp WAF Research Notes

Research Update - 2026-09-09

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2025-67066oasys sysoa version 1.0 Arbitrary Code Execution Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-70149membership management system SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-70150membership management system Missing Authorization Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-70152scholars tracking system SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-79569Movie_Recommend v1.0.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86738Snipe-IT before 8.7.0 CSS Injection via Custom CSS333140 , 340095 , 342259
CVE-2026-53581ntp: write path traversal340007 , 344360 , 390709
CVE-2025-70151scholars tracking system Arbitrary Code Execution Vulnerability351000
CVE-2026-86542knowns before 0.30.0 Path Traversal via Import Name340007 , 344360 , 390709
CVE-2025-34115OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.php340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-86538knowns before 0.30.0 Path Traversal via templateFile parameter344360 , 390709
CVE-2026-86732Craft CMS before 5.10.12 Remote Code Execution via element-index340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-61517Netis NX10 OS Command Injection via Ping Diagnostic Handler340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-86299Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-86437Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive Upload340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-86438Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Install Action340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-86733Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-58113Teamcenter V2412 Cross-site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-86207N-able N-central - Authentication Bypass344365
CVE-2026-86206N-able N-central - Access Control Bypass via Path Confusion and Forwarded Header Spoofing344365
CVE-2026-86539knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-86806opengeos GeoLibre _is_within_roots server-side request forgery337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 350591 , 390722 , 398021 , 398022
CVE-2026-78838AppNitro MachForm v30 Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-86590Eclipse Che Server-Side Request Forgery Vulnerability337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-86735snipe-it before 8.7.0 SSRF via IPv6 transition address bypass337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-54611InstantCMS has Remote Code Execution in package installer340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-86290SourceCodester Online Voting System ajax.php save_category sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122
CVE-2026-86298SourceCodester Class and Exam Timetabling System delete_subject.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86305light0011 cms Upload.class.php upload unrestricted upload351000
CVE-2026-86666aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload351000
CVE-2026-73319XenForo < 2.3.13 XSS via Dynamic Redirect Handler333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-48707InstantCMS vulnerable to SSRF via upload redirect bypass allows internal network service scanning337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-86291itsourcecode Sales and Inventory System us_edit1.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86294SourceCodester Simple Traffic Offense System Settings Update Endpoint save-settings.php cross site scripting333140 , 333141 , 340095 , 342259
CVE-2026-86309itsourcecode Sales and Inventory System pro_searchfrm.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86310itsourcecode Sales and Inventory System cust_edit1.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86517itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86518code-projects Student Crud Operation edit.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86668aircheng-org iWebShop-5 pic.php uploadFile cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-86675itsourcecode Sales and Inventory System us_edit.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86301code-projects Hospital Information System Patient Management editPatient.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-86644star7th showdoc API Page Save Endpoint editormd.js cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-86667aircheng-org iWebShop-5 member.php member_list sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572