Atomicorp WAF Research Notes
Research Update - 2026-09-10
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-50894 | easyadmin v2.0.2.2 Arbitrary Code Execution Vulnerability | 351000 |
| CVE-2026-79570 | mfish-nocode-pro v1.0.0 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-54694 | NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-78997 | UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-87930 | MaxSite CMS through 109.6 PHP Object Injection via ci_session | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 |
| CVE-2026-78834 | Code Injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-86775 | knowns before 0.30.0 Path Traversal via Document API | 340007 , 344360 , 390709 |
| CVE-2026-87927 | MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-87807 | siyuan before v3.8.2 SQL Injection via fullTextSearchBlock | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 341250 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-26212 | Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCE | 351000 |
| CVE-2026-79322 | mageplaza blog SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-87811 | SiYuan before v3.8.2 Stored XSS via notebook template paths | 333140 , 340087 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-87814 | SiYuan before v3.8.2 Stored XSS via Asset Preview | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86771 | Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-18147 | Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execution via crafted url | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-0702 | VidShop for WooCommerce <= 1.1.4 - SQL Injection | 341245 |
| CVE-2026-78837 | A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-87812 | SiYuan before v3.8.2 Stored XSS via Bazaar iconURL | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-87821 | Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-87999 | Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-87870 | Ninja Forms - Scheduled Exports <= 3.0.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via REST API Paramete | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-75170 | the HubCore platform (version 14.1.1) Cross-Site Scripting Vulnerability | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-78738 | Silverpeas Core 6.4.6 Cross-Site Scripting Vulnerability | 340099 , 341099 |
| CVE-2026-78742 | Silverpeas Core <=6.4.6 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86756 | Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState | 344365 |
| CVE-2026-87926 | Rizwan17 inventory-management-system Login Page index.php cross site scripting | 333140 , 333141 , 340087 , 340099 , 340147 , 341099 , 341266 , 342259 |