Atomicorp WAF Research Notes
Research Update - 2026-09-17
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2023-27168 | write-back manager Arbitrary Code Execution Vulnerability | 351000 |
| CVE-2026-58146 | Unauthorized remote code execution in T-Mobile 5G Box IDU routers | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-58147 | Authorized remote code execution via password change functionality in T-Mobile 5G Box IDU routers | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-92576 | HKUDS nanobot before 0.3.0 Server-Side Request Forgery via WebFetchTool | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-85731 | oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) | 340014 , 340023 , 340029 , 340193 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390719 , 393655 |
| CVE-2026-92566 | DataGear through 6.0.0 Unauthenticated SSRF via HTTP Dataset Preview | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-92580 | AVideo through 29.0 CloneSite Stored Shell Injection via SSH Password CSRF | 340014 , 340023 , 340029 , 341245 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-92719 | Quickwit through 0.9.0 SSRF via SQS queue_url Parameter | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-92791 | Uber Kraken through 0.1.29 Path Traversal via tag parameter | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-92815 | changedetection.io through 0.60.6 SSRF via browser-step Goto URL | 337109 , 337110 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-92397 | Ruijie RG-EW3000GX configChange unifyframe-sgi.elf cc_set os command injection | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-92398 | Ruijie RG-EW3000GX user_list_note admin os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2023-27170 | write-back manager Path Traversal Vulnerability | 340007 , 344360 , 390709 |
| CVE-2026-92604 | Scirius through 3.8.0 Arbitrary File Write via PCAP Upload | 340007 , 344360 , 390709 |
| CVE-2026-92775 | Wiki.js through 2.5.314 Server-Side Request Forgery via Image Prefetch | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-92804 | Nango through 0.70.4 Server-Side Request Forgery via Configuration | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-92813 | Metabase through 0.63.18 SSRF via GeoJSON URL validation bypass | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-39038 | BharatMLStack up to and including v1.3.0 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-92380 | WuzhiCMS Remote Image Fetch index.php saveRemote server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-92405 | SourceCodester Inventory and Monitoring System index.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-92406 | SourceCodester Inventory and Monitoring System btn_functions.php add sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-92569 | Hippo4j through 1.5.0 SSRF via clientAddress Parameter | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-92584 | AVideo through 29.0 Stored Cross-Site Scripting via User-Agent Header | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-92364 | itsourcecode Leave Management System index.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-92526 | itsourcecode Leave Management System index.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-92527 | chatwoot Shopify OAuth callbacks_controller.rb server-side request forgery | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-92418 | ChangeWeDer crm Save Endpoint customer.serve.js cross site scripting | 333140 , 340095 , 340147 , 341256 , 342259 , 346755 |
| CVE-2025-56563 | Server-Side Request Forgery | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |