Atomicorp WAF Research Notes

Research Update - 2026-09-24

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2000-1024ewave servletexec Security Vulnerability351000
CVE-2026-18872IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-96754orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-79766Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-controlled domain/email340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-77601OpenC3 COSMOS: Authenticated OS command injection via the pypi_url setting340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2005-10004Cacti graph_view.php RCE via graph_start Parameter Injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2015-10145Gargoyle 1.5.x Authenticated OS Command Execution via run_commands.sh340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-63498Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-84683Automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job st333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-88415MCMS 6.1.1 through 6.2.1 Cross-Site Scripting Vulnerability333140
CVE-2026-96673Photoview through 2.4.0 SQL Injection via album download route340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-68700RAGFlow Remote Code Execution Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-77581BentoPDF: SSRF in cors-proxy-worker.js via DNS-based hostname allowlist bypass337109 , 337110 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-56739Logto: SSRF via Webhooks and Custom OAuth2 Connector UserInfo Endpoint337109 , 337110 , 340162 , 340163 , 344360 , 344362 , 344370 , 398021 , 398022
CVE-2026-76086Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-5695Multiple vulnerabilities in the Microweber administration panel351000
CVE-2026-56736phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-62368Snipe-IT: Stored XSS via Custom Field name in asset-list column headers333140 , 340095 , 340147 , 341256 , 342259 , 346755
CVE-2026-77294TREK: Server-Side Request Forgery via User-Configurable LLM Base URL337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-87902WordPress Core - PHP Template Path Traversal340007
CVE-2026-90959Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and pul340007 , 344360 , 347009 , 390709
CVE-2026-79764Termix: Authenticated SSRF via /homepage/proxy — No Destination Allowlist337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-77394OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-75887Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handler340007 , 344360 , 347009 , 390709
CVE-2026-91775LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-96651Plex Media Server path traversal337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-79761Termix: Command injection in SSH key deployment verification340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-79760Termix: Authenticated blind SSRF through notification channel test endpoints337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-85738TREK: SSRF Guard Bypass via IPv6 Transition Addresses (NAT64/6to4)337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-5696Multiple vulnerabilities in the Microweber administration panel333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-96602Abdurrab5 online-makeup-store Customer Login customerSignin.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-96751pmTicket Project-Management-Software add_project.php setSync sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-96803java110 MicroCommunity fallBack API Endpoint BusinessApi.java QueryServiceSMOImpl.fallBack sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-96898yhx070424 ShopXO Ueditor Upload ueditor.php path traversal340007 , 344360 , 347009 , 390709
CVE-2026-47132phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-96652Plex Media Server SSRF337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-77825IBM ContextForge MCP Gateway is affected by path traversal344360 , 347009
CVE-2026-63001REDAXO: Stored XSS via Unescaped Media Manager Type Name in mediaIsInUse()333140 , 333141 , 340087 , 340095 , 340099 , 341099 , 341266 , 346755
CVE-2026-63002REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-67224RabbitMQ: Admin path-traversal write via trace name347009
CVE-2026-96678weiqingwen spring-boot-forum Avatar Upload NewUserFormValidator.java validate path traversal340007 , 344360 , 347009 , 390709
CVE-2026-96773Intelliants Subrion CMS Login Page login.php authorize redirect340162 , 340163 , 344365
CVE-2026-96777Forma LMS Multi-User-Selector AJAX Endpoint getData getDataTask sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-97232volotat Anagnorisis page.html start_streaming path traversal340007 , 344360 , 390709
CVE-2025-15394iCMS POST Parameter ConfigAdmincp.php save code injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-96810huanzi-qch base-admin Add User CommonController.java save cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148