Atomicorp WAF Research Notes
Research Update - 2026-09-24
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2000-1024 | ewave servletexec Security Vulnerability | 351000 |
| CVE-2026-18872 | IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-96754 | orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-79766 | Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-controlled domain/email | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-77601 | OpenC3 COSMOS: Authenticated OS command injection via the pypi_url setting | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2005-10004 | Cacti graph_view.php RCE via graph_start Parameter Injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2015-10145 | Gargoyle 1.5.x Authenticated OS Command Execution via run_commands.sh | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-63498 | Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-84683 | Automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job st | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-88415 | MCMS 6.1.1 through 6.2.1 Cross-Site Scripting Vulnerability | 333140 |
| CVE-2026-96673 | Photoview through 2.4.0 SQL Injection via album download route | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-68700 | RAGFlow Remote Code Execution Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-77581 | BentoPDF: SSRF in cors-proxy-worker.js via DNS-based hostname allowlist bypass | 337109 , 337110 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-56739 | Logto: SSRF via Webhooks and Custom OAuth2 Connector UserInfo Endpoint | 337109 , 337110 , 340162 , 340163 , 344360 , 344362 , 344370 , 398021 , 398022 |
| CVE-2026-76086 | Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-5695 | Multiple vulnerabilities in the Microweber administration panel | 351000 |
| CVE-2026-56736 | phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-62368 | Snipe-IT: Stored XSS via Custom Field name in asset-list column headers | 333140 , 340095 , 340147 , 341256 , 342259 , 346755 |
| CVE-2026-77294 | TREK: Server-Side Request Forgery via User-Configurable LLM Base URL | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-87902 | WordPress Core - PHP Template Path Traversal | 340007 |
| CVE-2026-90959 | Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and pul | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-79764 | Termix: Authenticated SSRF via /homepage/proxy — No Destination Allowlist | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-77394 | OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-75887 | Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handler | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-91775 | LimeSurvey Community Edition 7.0.14 - Reflected XSS through unescaped LSS survey-import warnings | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-96651 | Plex Media Server path traversal | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-79761 | Termix: Command injection in SSH key deployment verification | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-79760 | Termix: Authenticated blind SSRF through notification channel test endpoints | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-85738 | TREK: SSRF Guard Bypass via IPv6 Transition Addresses (NAT64/6to4) | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-5696 | Multiple vulnerabilities in the Microweber administration panel | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-96602 | Abdurrab5 online-makeup-store Customer Login customerSignin.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-96751 | pmTicket Project-Management-Software add_project.php setSync sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-96803 | java110 MicroCommunity fallBack API Endpoint BusinessApi.java QueryServiceSMOImpl.fallBack sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-96898 | yhx070424 ShopXO Ueditor Upload ueditor.php path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-47132 | phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-96652 | Plex Media Server SSRF | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-77825 | IBM ContextForge MCP Gateway is affected by path traversal | 344360 , 347009 |
| CVE-2026-63001 | REDAXO: Stored XSS via Unescaped Media Manager Type Name in mediaIsInUse() | 333140 , 333141 , 340087 , 340095 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-63002 | REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-67224 | RabbitMQ: Admin path-traversal write via trace name | 347009 |
| CVE-2026-96678 | weiqingwen spring-boot-forum Avatar Upload NewUserFormValidator.java validate path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-96773 | Intelliants Subrion CMS Login Page login.php authorize redirect | 340162 , 340163 , 344365 |
| CVE-2026-96777 | Forma LMS Multi-User-Selector AJAX Endpoint getData getDataTask sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-97232 | volotat Anagnorisis page.html start_streaming path traversal | 340007 , 344360 , 390709 |
| CVE-2025-15394 | iCMS POST Parameter ConfigAdmincp.php save code injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-96810 | huanzi-qch base-admin Add User CommonController.java save cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |