Atomicorp WAF Research Notes
Research Update - 2026-09-19
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2025-55787 | SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-66455 | LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/con | 340014 , 340023 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390614 |
| CVE-2026-75031 | Interchange Arbitrary Code Execution Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-9103 | Langflow OSS - Superuser Token Issuance | 300008 |
| CVE-2023-54399 | Hongjing e-HR < 8.2 SQL Injection via /servlet/codesettree | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-75885 | Openshift/console: openshift/console: unauthenticated ssrf and resource exhaustion via devfile parser endpoint | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-52483 | Security Vulnerability | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-81656 | IBM Guardium Data Protection is affected by multiple vulnerabilities. | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-88622 | NUUO Network Video Recorder 2.0.0 Command Injection Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2017-20284 | Caucho Resin resin-doc Unauthenticated Path Traversal via jndi-appconfig Servlet | 340007 , 344360 , 347009 , 390709 |
| CVE-2019-25776 | Weaver E-cology SQL Injection via SyncUserInfo.jsp | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2021-48008 | Chanjet CRM SQL Injection via get_usedspace.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-62278 | LubeLogger: Path Traversal in HandleTranslationFileUpload Allows Authenticated Users to Write Files Outside Data Directo | 344360 , 390709 |
| CVE-2026-93872 | Cotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb Parameter | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 |
| CVE-2026-81669 | IBM Guardium Data Protection is affected by multiple vulnerabilities. | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-93591 | SiYuan before 3.8.3 SQL Injection via unescaped tag in graph.go | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-63445 | Perses: Unvalidated project parameter enables filesystem path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-76900 | CordysCRM: SSRF via Approval Flow Webhook Execution due to Missing SSRF Validation at Runtime | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-62282 | OpenCVE: Server-Side Request Forgery (SSRF) in notifications | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-77386 | Kyoo: OIDC login token can be redirected to an attacker-controlled URL | 340162 , 340163 , 340165 , 344365 |
| CVE-2021-3030 | Cute Editor for ASP.NET 6.4 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-76899 | CordysCRM: Authenticated SQL injection via sort.name on POST /account-pool/page | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-52745 | CordysCRM: Customer Public Pool Sorting Field SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-93597 | ArcadeDB before 26.9.1 SSRF via IPv6 transition addresses | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-93871 | Cotonti through 1.0.0 Stored Open Redirect via Page redir: Prefix | 344365 |
| CVE-2026-88623 | NUUO Network Video Recorder 2.0.0 Security Vulnerability | 340007 , 344360 , 390709 |