Atomicorp WAF Research Notes
Research Update - 2026-09-28
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-101001 | Netcore NBR200V2 Web Management network_tools eval os command injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-101090 | Nezha through 2.2.3 Host Header Injection via OAuth2 redirect_uri | 344365 |
| CVE-2026-100896 | TOTOLINK N150RT Web Management formWlSiteSurvey system os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-100875 | mathurvishal CloudClassroom-PHP-Project updatedetailsfromfaculty.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-100893 | Privoce VoceChat Server open_graphic_parse Endpoint resource.rs fetch server-side request forgery | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-100901 | athlon1600 youtube-downloader stream.php stream server-side request forgery | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-100909 | OctoberCMS ResizeImages.php getSourcePathForResize server-side request forgery | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-100904 | amirsanni mini-inventory-and-sales-management-system Items Management Items.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-101046 | Fleet before 4.89.0 SQL Injection via ORDER BY Activity Endpoints | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-101061 | utcp-gql and utcp-websocket before 1.1.1 SSRF via URL validation bypass | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-100877 | mathurvishal CloudClassroom-PHP-Project registrationform.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-100887 | amirsanni Mini-Inventory-and-Sales-Management-System Database Query Builder DB_query_builder.php order_by sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-100894 | mathurvishal CloudClassroom-PHP-Project updateguest.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-100898 | DevaslanPHP project-management Timesheet Dashboard ActivitiesReport.php whereRaw sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-100880 | zhistaredu StarTraining Upload Endpoint MimeTypeUtils.java cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-100900 | DevaslanPHP project-management Jira Import jira-import updateJiraProjects server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-100882 | Krayin laravel-crm Admin Settings Endpoint index.blade.php cross site scripting | 333140 , 333141 , 340095 |