New WAF Objects: [total: 10] ================================== Policy: name: 'CVE-2026-35273: Oracle Addresses PeopleSoft - RCE' id: '20000377' minimum version: '10.0' predicates: - type: HTTP Request operation: Match All match values: - part: url operation: MatchRegExp value: (?:/PSEMHUB/hub|/PSIGW/HttpListeningConnector) - part: parameter name: Envelope/Body/EnvironmentManagement/sourceURL operation: includes value: http - type: HTTP Request operation: Match Any match values: - part: parameter name: Envelope/Body/EnvironmentManagement/sourceURL operation: MatchRegExp value: |- :\/\/\b(?:169\.254\.169\.254|0xa9fea9fe|0xa9\.0xfe\.0xa9\.0xfe|0251\.0077\.0251\.0376|2852037118)\b - part: parameter name: Envelope/Body/EnvironmentManagement/sourceURL operation: MatchRegExp value: |- :\/\/(?:localhost|127(?:\.\d+){1,3}|10(?:\.\d+){3}|172\.(?:1[6-9]|2\d|3[01])(?:\.\d+){2}|192\.168(?:\.\d+){2}|0\.0\.0\.0|::1|fe80::.*|fc00::.*|fec0::.*) - part: parameter name: Envelope/Body/EnvironmentManagement/sourceURL operation: MatchRegExp value: :\/\/\b0[0-7]{1,3}\.0[0-7]{1,3}\.0[0-7]{1,3}\.0[0-7]{1,3}\b - part: parameter name: Envelope/Body/EnvironmentManagement/sourceURL operation: MatchRegExp value: |- :\/\/\b(?:213[0-4]\d{6}|214[0-6]\d{6}|2147[0-3]\d{5}|21474[0-7]\d{4}|214748[0-2]\d{3}|2147483[0-5]\d{2}|21474836[0-3]\d|214748364[0-7])\b|\b(?:16[89]\d{6}|17[0-9]\d{6}|18[0-3]\d{6}|184[0-4]\d{5}|1845[0-4]\d{4}|18454[0-8]\d{3}|184549[0-2]\d{2}|1845493[0-6]\d|18454937[0-5])\b|\b(?:32322355[2-9]\d|3232235[6-9]\d{2}|323223[6-9]\d{3}|32322[4-9]\d{4}|3232[3-9]\d{5}|323[3-9]\d{6}|32[4-9]\d{7}|3[3-9]\d{8})\b - part: parameter name: Envelope/Body/EnvironmentManagement/sourceURL operation: MatchRegExp value: |- :\/\/\b0x(?:7f[0-9a-f]{6}|0a[0-9a-f]{6}|ac1[0-9a-f]{5}|c0a8[0-9a-f]{4}|a9fe[0-9a-f]{4})\b|\b0x[0-9a-f]{1,2}\.0x[0-9a-f]{1,2}\.0x[0-9a-f]{1,2}\.0x[0-9a-f]{1,2}\b - type: HTTP Request Method operation: At Least One values: - POST Signature: ID: '708564' Name: OOB Domain .callback.red Attack: Illegal Resource Access - Blocking Attack Class: Illegal Resource Access Dictionary: Recommended for Blocking for Web Applications Pattern: part=".callback.red", rgxp="\.callback\.red" Policy: Recommended Signatures Policy for Web Applications Search In: - headers - url-and-parameters Policy: name: 'CVE-2025-8943: Flowise OS command remote code execution' id: '20000375' minimum version: '10.0' predicates: - type: HTTP Request Method operation: At Least One values: - POST - type: HTTP Request operation: Match All match values: - part: parameter name: inputs.mcpServerConfig.command operation: MatchRegExp value: . - part: url operation: includes value: /node-load-method/customMCP Policy: name: CVE-2026-26980 - Ghost CMS - SQLi id: '20000374' minimum version: '10.0' predicates: - type: HTTP Request operation: Match All match values: - part: parameter name: filter operation: MatchRegExp value: (?:SELECT|FROM|OR|AND|WHERE|CASE|\|\|) - part: url operation: MatchRegExp value: (?:\/ghost\/api\/content\/posts|\/ghost\/api\/content\/tags) - part: parameter name: filter operation: includes value: slug:[ Policy: name: 'CVE-2026-10520: Ivanti Sentry - OS Command Injection' id: '20000373' minimum version: '10.0' predicates: - type: HTTP Request operation: Match All match values: - part: parameter name: message operation: includes value: - part: parameter name: message operation: includes value: - part: url operation: includes value: /mics/api/v2/sentry/mics-config/handleMessage - type: HTTP Request Method operation: At Least One values: - POST Signature: ID: '708563' Name: 'CVE-2025-5394: WordPress Alone Theme - Unrestricted File Upload #2' Attack: Illegal Resource Access - Blocking Attack Class: Illegal Resource Access Dictionary: Recommended for Blocking for Web Applications Pattern: part="/wp-admin/admin-ajax.php", part="action=beplus_import_pack_install_plugin", rgxp="data\[plugin_source\]\=[\s\S]{0,100}[http][\s\S]{0,100}(\.zip)" Policy: Recommended Signatures Policy for Web Applications Search In: - url-and-parameters Signature: ID: '708561' Name: 'CVE-2025-5287: WordPress Likes and Dislikes Plugin - Unauthenticated SQL Injection' Attack: SQL Injection - Blocking Attack Class: SQL Injection Dictionary: Recommended for Blocking for Web Applications Pattern: part="/wp-admin/admin-ajax.php", part="action=my_likes_dislikes_action", rgxp="post\=[\s\S]{0,50}(?:select|from|delete|or|and|alter|insert|drop)" Policy: Recommended Signatures Policy for Web Applications Search In: - url-and-parameters Signature: ID: '708560' Name: 'CVE-2026-22557: Unifi - Unauthenticated Path Traversal' Attack: Directory Traversal Attack Class: Directory Traversal Dictionary: Recommended for Blocking for Web Applications Pattern: part="/guest/s/default/wechat/sign", rgxp="page_error=\.\.\/" Policy: Recommended Signatures Policy for Web Applications Search In: - url-and-parameters Signature: ID: '708559' Name: 'CVE-2026-42271: LiteLLM - Authenticated RCE' Attack: Remote Command Execution - Blocking Attack Class: Remote Command Execution Dictionary: Recommended for Blocking for Web Applications Pattern: part="/mcp-rest/test/", part="transport=stdio", part="command=", part="args=", rgxp="\/mcp-rest\/test\/(tools\/list|connection)" Policy: Recommended Signatures Policy for Web Applications Search In: - url-and-parameters Signature: ID: '708558' Name: Division-Based Blind SQLi Attack: SQL Injection - Blocking Attack Class: SQL Injection Dictionary: Recommended for Blocking for Web Applications Pattern: part="GREATEST", part="ASCII", part="SUBSTRING", rgxp="(?:/GREATEST\(ASCII\(SUBSTRING\((?:VERSION\(|CURRENT_DATABASE\(|CURRENT_USER|INET_SERVER_ADDR\())" Policy: Recommended Signatures Policy for Web Applications Search In: - parameters