Atomicorp WAF Research Notes
Research Update - 2026-09-30
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-39117 | AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 Arbitrary Code Execution Vulnerability | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-79538 | metatool-ai MetaMCP up to and including 2.4.22 Security Vulnerability | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-103056 | AiSOC 7.2.0 before 12.0.0 Command Injection via CrowdStrike RTR | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2023-54400 | Fumeng Cloud SQL Injection via AjaxMethod.ashx getEmpByname | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-85520 | Unauthenticated arbitrary file write leading to RCE in gmfeed PrestaShop module | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-40281 | Gotenberg <= 8.30.1 - Remote Code Execution | 393655 |
| CVE-2020-37242 | WordPress Plugin Supsystic Ultimate Maps 1.1.12 SQL Injection via sidx | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2020-37243 | WordPress Plugin Supsystic Pricing Table 1.8.7 SQL Injection XSS | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2020-37244 | WordPress Plugin Supsystic Membership 1.4.7 SQL Injection via sidx | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82804 | Apache DolphinScheduler: Command Injection in the Alert Script Plugin | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2015-20122 | Seeyon A6 OA Unauthenticated SQL Injection via downloadAtt.jsp | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-102911 | zosmaai pi-llm-wiki wiki_capture_source MCP tool index.ts os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-55096 | SSRF via DNS-resolution gap in _validate_url_security (file download by URL) | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-102570 | ClipBucket v5 through 5.5.3-#197 SQL Injection via language_id Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-11977 | HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion | 340748 , 344360 , 347006 , 390709 |
| CVE-2026-51772 | Server-Side Request Forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-102616 | risesoft-y9 WorkFlow-Engine OAuth2 Resource Filter CustomHistoricProcessServiceImpl.java getByIdAndYear sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-102874 | HKUDS AnyTool Execute Endpoint main.py subprocess.run os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-102909 | SourceCodester Online Reviewer Management System btn_functions.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-102913 | SourceCodester Car Driving School Management System Master.php save_enrollment sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-53989 | Dockhand < 1.0.36 Open Redirect via OIDC Initiation Endpoint | 344365 |
| CVE-2026-96655 | Plex Media Server arbitrary-host SSRF | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2020-37235 | WordPress Theme Wibar 1.1.8 Stored Cross-Site Scripting via Brand Component | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2020-37236 | NewsLister Authenticated Persistent Cross-Site Scripting via Admin Panel | 333141 , 340087 , 340095 , 340099 , 340247 , 340248 , 341099 , 341266 , 342259 |
| CVE-2026-102906 | 0xshariq github-mcp-server Git Remove MCP Tool github.ts child_process.exec os command injection | 340014 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-102912 | SourceCodester Online Leave Management System page reports sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |