Atomicorp WAF Research Notes

Research Update - 2026-09-30

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-39117AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 Arbitrary Code Execution Vulnerability337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-79538metatool-ai MetaMCP up to and including 2.4.22 Security Vulnerability340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-103056AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2023-54400Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-85520Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-40281Gotenberg <= 8.30.1 - Remote Code Execution393655
CVE-2020-37242WordPress Plugin Supsystic Ultimate Maps 1.1.12 SQL Injection via sidx340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2020-37243WordPress Plugin Supsystic Pricing Table 1.8.7 SQL Injection XSS340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2020-37244WordPress Plugin Supsystic Membership 1.4.7 SQL Injection via sidx340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-82804Apache DolphinScheduler: Command Injection in the Alert Script Plugin340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2015-20122Seeyon A6 OA Unauthenticated SQL Injection via downloadAtt.jsp340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-102911zosmaai pi-llm-wiki wiki_capture_source MCP tool index.ts os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-55096SSRF via DNS-resolution gap in _validate_url_security (file download by URL)337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-102570ClipBucket v5 through 5.5.3-#197 SQL Injection via language_id Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-11977HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion340748 , 344360 , 347006 , 390709
CVE-2026-51772Server-Side Request Forgery337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-102616risesoft-y9 WorkFlow-Engine OAuth2 Resource Filter CustomHistoricProcessServiceImpl.java getByIdAndYear sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-102874HKUDS AnyTool Execute Endpoint main.py subprocess.run os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-102909SourceCodester Online Reviewer Management System btn_functions.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-102913SourceCodester Car Driving School Management System Master.php save_enrollment sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-53989Dockhand < 1.0.36 Open Redirect via OIDC Initiation Endpoint344365
CVE-2026-96655Plex Media Server arbitrary-host SSRF337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2020-37235WordPress Theme Wibar 1.1.8 Stored Cross-Site Scripting via Brand Component333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2020-37236NewsLister Authenticated Persistent Cross-Site Scripting via Admin Panel333141 , 340087 , 340095 , 340099 , 340247 , 340248 , 341099 , 341266 , 342259
CVE-2026-1029060xshariq github-mcp-server Git Remove MCP Tool github.ts child_process.exec os command injection340014 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-102912SourceCodester Online Leave Management System page reports sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572