Atomicorp WAF Research Notes
Research Update - 2026-09-11
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-71805 | Path Traversal | 351000 |
| CVE-2026-88062 | OmniRoute ACP Custom-Agent Remote Code Execution (RCE) | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-88866 | WWBN AVideo LoginControl Stored XSS via User-Agent Header | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-88867 | WWBN AVideo Stored XSS via Category Name and Icon Class | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-88868 | AVideo LiveLinks Stored XSS via title and description fields | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-88869 | AVideo AD_Server Stored XSS via log.php label parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-84889 | A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbit | 340007 , 344360 , 390709 , 390719 |
| CVE-2026-23921 | Blind, read-only SQL injection in Zabbix API via sortfield parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-64837 | ICEcoder through 8.1 OS Command Injection via lib/properties.php | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 |
| CVE-2026-64838 | ICEcoder through 8.1 Path Traversal via oldFileName Parameter | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-79987 | Low-privilege RCE through element-search eager loading | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-81213 | Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-88937 | knowns through 0.33.0 Path Traversal via Template Engine | 344360 , 390709 |
| CVE-2026-88890 | OpenPanel SQL Injection via unvalidated profile filter column identifier | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-29962 | HSC MailInspector - Local File Inclusion | 344360 , 347009 , 390709 |
| CVE-2026-81265 | Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-88938 | knowns through 0.33.0 Path Traversal via code.find MCP tool | 340007 , 344360 , 390709 |
| CVE-2026-88940 | knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-54054 | Transmute has full-read SSRF in URL file import (POST /api/files/url) — no host/IP validation, follows redirects | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-75307 | zhitan-ems 1.0.0 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-88055 | AnythingLLM: Stored XSS Due to Unescaped Server-Side HTML Concatenation in MetaGenerator | 333140 , 333141 , 340095 , 342259 |
| CVE-2026-88892 | OpenPanel SSRF via Unguarded Importer File URL Fetch | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-41456 | Bludit CMS <= 3.20.0 - Cross-Site Scripting | 340099 , 340147 , 341099 , 346755 , 347198 |
| CVE-2026-79723 | Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-38626 | Garlic-Hub v1.0.1 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |