Atomicorp WAF Research Notes
Research Update - 2026-09-29
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-85526 | Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD | 340007 , 344360 , 390709 |
| CVE-2024-44659 | online shopping portal SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572 |
| CVE-2026-12227 | Visual Composer <= 45.16.0 - Unauthenticated LFI | 344360 , 347009 , 390709 |
| CVE-2026-85185 | Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root | 340006 , 390719 |
| CVE-2026-88804 | Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-101072 | Netcore NR289-GE CGI ap_ip.cgi system os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-101075 | Netcore NR289-GE Location Time location_time.cgi system os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-101076 | Netcore NR289-GE CGI set_ntp_server_ip.cgi system os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-102240 | Netcore NAP930 Network Tools CGI network_tools eval os command injection | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-54710 | FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclusion) | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-101009 | aaPanel BaoTa Unzip panelTask.py panelTask.bt_task._unzip os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-55160 | Authenticated Server-Side Request Forgery (SSRF) via feed URL in Stringer | 337109 , 337110 , 340162 , 340163 , 344360 , 350147 , 398021 , 398022 |
| CVE-2026-101860 | RaspAP raspap-webgui sudo Configuration PluginInstaller.php addSudoers privileges management | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2024-58386 | ZoneMinder 1.37.x Path Traversal via files view | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-101091 | SiYuan before v3.8.4 SQL Injection via Block Query Embed | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 380026 , 380122 , 390572 |
| CVE-2026-101898 | Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-82382 | Apache Roller: Reflected cross-site scripting in the frontpage directory parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2025-14664 | Campcodes Supplier Management System view_unit.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-14666 | itsourcecode COVID Tracking System page sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-14667 | itsourcecode COVID Tracking System page sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-14668 | campcodes Advanced Online Examination System loginExe.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-101005 | October CMS SSRF Protection ResizeImages.php validateExternalImageHost server-side request forgery | 337109 , 337110 , 340162 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-101012 | mathurvishal CloudClassroom-PHP-Project makeresult.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-101013 | mathurvishal CloudClassroom-PHP-Project updateresultdetails.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-101067 | dbgate save-uploaded-file Endpoint files.js saveUploadedFile path traversal | 340007 , 344360 , 390709 |
| CVE-2026-101068 | dbgate Create Connection Endpoint zipJsonLinesData.js zipJsonLinesData path traversal | 340007 , 344360 , 390709 |
| CVE-2026-101070 | dbgate Files Endpoint runners.js files path traversal | 340007 , 344360 , 390709 |
| CVE-2026-101082 | PMWeb downloader.aspx path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-102333 | httpdbg before 2.2.1 Stored Cross-Site Scripting via javascript URL | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-55156 | Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-7171 | Stored Cross-Site Scripting (XSS) in TPVEnlanube | 310717 , 310718 , 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-7172 | Stored Cross-Site Scripting (XSS) in TPVEnlanube | 310717 , 310718 , 340087 , 340099 , 341099 , 341266 , 346755 |
| CVE-2026-102332 | Dozzle before 11.1.2 Path Traversal via Log ZIP Download | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-86334 | CLI Path Traversal via Content-Disposition in LXD Image Export/Copy | 340006 , 390719 |
| CVE-2026-101071 | Acrel Electric Unet Web Service Upload Endpoint upload unrestricted upload | 351000 |
| CVE-2026-101105 | code-projects Matrimonial System Profile Creation Endpoint create_profile processprofile_form sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-101859 | RaspAP raspap-webgui OpenVPN Configuration del_ovpncfg.php escapeshellcmd os command injection | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-101861 | Langflow Code Execution via eval() in Component Input Schema | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-102244 | MODSetter SurfSense Document Export Feature editor_routes.py server-side request forgery | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-102366 | mall4j through 4.0 Unrestricted File Upload in Admin File Endpoints | 333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-101010 | aaPanel BaoTa data.py getData sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-101011 | aaPanel BaoTa Domain domainMod.py get_domain_status sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-101018 | dayrui XunruiCMS Group Editing Home.php group_all_edit sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-101141 | Eleveo Call Recording Software Play Audio audio.jsp cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-102264 | mwasikz robo-cafe-rms Edit Profile Feature update-account.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |