Atomicorp WAF Research Notes

Research Update - 2026-09-29

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-85526Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD340007 , 344360 , 390709
CVE-2024-44659online shopping portal SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572
CVE-2026-12227Visual Composer <= 45.16.0 - Unauthenticated LFI344360 , 347009 , 390709
CVE-2026-85185Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root340006 , 390719
CVE-2026-88804Unauthenticated update of public UI settings leading to stored cross-site scripting in Rancher333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-101072Netcore NR289-GE CGI ap_ip.cgi system os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-101075Netcore NR289-GE Location Time location_time.cgi system os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-101076Netcore NR289-GE CGI set_ntp_server_ip.cgi system os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-102240Netcore NAP930 Network Tools CGI network_tools eval os command injection340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-54710FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclusion)340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-101009aaPanel BaoTa Unzip panelTask.py panelTask.bt_task._unzip os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-55160Authenticated Server-Side Request Forgery (SSRF) via feed URL in Stringer337109 , 337110 , 340162 , 340163 , 344360 , 350147 , 398021 , 398022
CVE-2026-101860RaspAP raspap-webgui sudo Configuration PluginInstaller.php addSudoers privileges management340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2024-58386ZoneMinder 1.37.x Path Traversal via files view340007 , 344360 , 347009 , 390709
CVE-2026-101091SiYuan before v3.8.4 SQL Injection via Block Query Embed340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 380026 , 380122 , 390572
CVE-2026-101898Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-82382Apache Roller: Reflected cross-site scripting in the frontpage directory parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2025-14664Campcodes Supplier Management System view_unit.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-14666itsourcecode COVID Tracking System page sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-14667itsourcecode COVID Tracking System page sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-14668campcodes Advanced Online Examination System loginExe.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-101005October CMS SSRF Protection ResizeImages.php validateExternalImageHost server-side request forgery337109 , 337110 , 340162 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-101012mathurvishal CloudClassroom-PHP-Project makeresult.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-101013mathurvishal CloudClassroom-PHP-Project updateresultdetails.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-101067dbgate save-uploaded-file Endpoint files.js saveUploadedFile path traversal340007 , 344360 , 390709
CVE-2026-101068dbgate Create Connection Endpoint zipJsonLinesData.js zipJsonLinesData path traversal340007 , 344360 , 390709
CVE-2026-101070dbgate Files Endpoint runners.js files path traversal340007 , 344360 , 390709
CVE-2026-101082PMWeb downloader.aspx path traversal340007 , 344360 , 347009 , 390709
CVE-2026-102333httpdbg before 2.2.1 Stored Cross-Site Scripting via javascript URL333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-55156Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints340007 , 344360 , 347009 , 390709
CVE-2026-7171Stored Cross-Site Scripting (XSS) in TPVEnlanube310717 , 310718 , 340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-7172Stored Cross-Site Scripting (XSS) in TPVEnlanube310717 , 310718 , 340087 , 340099 , 341099 , 341266 , 346755
CVE-2026-102332Dozzle before 11.1.2 Path Traversal via Log ZIP Download340007 , 344360 , 347009 , 390709
CVE-2026-86334CLI Path Traversal via Content-Disposition in LXD Image Export/Copy340006 , 390719
CVE-2026-101071Acrel Electric Unet Web Service Upload Endpoint upload unrestricted upload351000
CVE-2026-101105code-projects Matrimonial System Profile Creation Endpoint create_profile processprofile_form sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-101859RaspAP raspap-webgui OpenVPN Configuration del_ovpncfg.php escapeshellcmd os command injection340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-101861Langflow Code Execution via eval() in Component Input Schema340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-102244MODSetter SurfSense Document Export Feature editor_routes.py server-side request forgery337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-102366mall4j through 4.0 Unrestricted File Upload in Admin File Endpoints333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148
CVE-2026-101010aaPanel BaoTa data.py getData sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-101011aaPanel BaoTa Domain domainMod.py get_domain_status sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-101018dayrui XunruiCMS Group Editing Home.php group_all_edit sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-101141Eleveo Call Recording Software Play Audio audio.jsp cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-102264mwasikz robo-cafe-rms Edit Profile Feature update-account.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755