Atomicorp WAF Research Notes

Research Update - 2026-09-10

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-50894easyadmin v2.0.2.2 Arbitrary Code Execution Vulnerability351000
CVE-2026-79570mfish-nocode-pro v1.0.0 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-54694NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-78997UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-87930MaxSite CMS through 109.6 PHP Object Injection via ci_session340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722
CVE-2026-78834Code Injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-86775knowns before 0.30.0 Path Traversal via Document API340007 , 344360 , 390709
CVE-2026-87927MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher340007 , 344360 , 347009 , 390709
CVE-2026-87807siyuan before v3.8.2 SQL Injection via fullTextSearchBlock340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 341250 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-26212Rara One Click Demo Import < 1.3.5 Arbitrary File Upload RCE351000
CVE-2026-79322mageplaza blog SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-87811SiYuan before v3.8.2 Stored XSS via notebook template paths333140 , 340087 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-87814SiYuan before v3.8.2 Stored XSS via Asset Preview333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-86771Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-18147Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execution via crafted url333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-0702VidShop for WooCommerce <= 1.1.4 - SQL Injection341245
CVE-2026-78837A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-87812SiYuan before v3.8.2 Stored XSS via Bazaar iconURL333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-87821Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-87999Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-87870Ninja Forms - Scheduled Exports <= 3.0.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via REST API Paramete333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-75170the HubCore platform (version 14.1.1) Cross-Site Scripting Vulnerability333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-78738Silverpeas Core 6.4.6 Cross-Site Scripting Vulnerability340099 , 341099
CVE-2026-78742Silverpeas Core <=6.4.6 Cross-Site Scripting Vulnerability333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-86756Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState344365
CVE-2026-87926Rizwan17 inventory-management-system Login Page index.php cross site scripting333140 , 333141 , 340087 , 340099 , 340147 , 341099 , 341266 , 342259