Atomicorp WAF Research Notes

Research Update - 2026-09-11

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-71805Path Traversal351000
CVE-2026-88062OmniRoute ACP Custom-Agent Remote Code Execution (RCE)340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-88866WWBN AVideo LoginControl Stored XSS via User-Agent Header333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-88867WWBN AVideo Stored XSS via Category Name and Icon Class333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-88868AVideo LiveLinks Stored XSS via title and description fields333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-88869AVideo AD_Server Stored XSS via log.php label parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-84889A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbit340007 , 344360 , 390709 , 390719
CVE-2026-23921Blind, read-only SQL injection in Zabbix API via sortfield parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-64837ICEcoder through 8.1 OS Command Injection via lib/properties.php340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009
CVE-2026-64838ICEcoder through 8.1 Path Traversal via oldFileName Parameter340007 , 344360 , 347009 , 390709
CVE-2026-79987Low-privilege RCE through element-search eager loading340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-81213Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-88937knowns through 0.33.0 Path Traversal via Template Engine344360 , 390709
CVE-2026-88890OpenPanel SQL Injection via unvalidated profile filter column identifier340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-29962HSC MailInspector - Local File Inclusion344360 , 347009 , 390709
CVE-2026-81265Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-88938knowns through 0.33.0 Path Traversal via code.find MCP tool340007 , 344360 , 390709
CVE-2026-88940knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint340007 , 344360 , 347009 , 390709
CVE-2026-54054Transmute has full-read SSRF in URL file import (POST /api/files/url) — no host/IP validation, follows redirects337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-75307zhitan-ems 1.0.0 Cross-Site Scripting Vulnerability333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-88055AnythingLLM: Stored XSS Due to Unescaped Server-Side HTML Concatenation in MetaGenerator333140 , 333141 , 340095 , 342259
CVE-2026-88892OpenPanel SSRF via Unguarded Importer File URL Fetch337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-41456Bludit CMS <= 3.20.0 - Cross-Site Scripting340099 , 340147 , 341099 , 346755 , 347198
CVE-2026-79723Langflow is vulnerable to server-side request forgery due to missing egress validation on server-side URL fetches337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-38626Garlic-Hub v1.0.1 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572