New WAF Objects: [total: 3] ================================== Policy: name: 'CVE-2026-54420: LiteSpeed cPanel plugin - RCE' id: '20000378' minimum version: '10.0' predicates: - type: HTTP Request operation: Match All match values: - part: header name: Content-Type operation: includes value: application/json - type: HTTP Request Method operation: At Least One values: - POST - type: HTTP Request operation: Match Any match values: - part: parameter name: template operation: includes value: '#set' - part: parameter name: template operation: includes value: ${ - part: parameter name: template operation: includes value: '{{' - type: HTTP Request operation: Match All match values: - part: url operation: includes value: /api/render Signature: ID: '708566' Name: 'CVE-2026-4020: Gravity SMTP <= 2.1.4 - Unauthenticated Sensitive Information Exposure via REST API' Attack: Illegal Resource Access - Blocking Attack Class: Illegal Resource Access Dictionary: Recommended for Blocking for Web Applications Pattern: part="/wp-json/gravitysmtp/v1/tests/mock-data", part="page", rgxp="page\=[\s\S]{0,50}gravitysmtp-settings" Policy: Recommended Signatures Policy for Web Applications Search In: - url-and-parameters Signature: ID: '708565' Name: CVE-2026-39808- Fortinet Fortisandbox- OS Command Injection Attack: Remote Command Execution - Blocking Attack Class: Remote Command Execution Dictionary: Recommended for Blocking for Web Applications Pattern: part="/fortisandbox/job-detail/tracer-behavior", part="jid", rgxp="jid=.*?[|;&$`\\]" Policy: Recommended Signatures Policy for Web Applications Search In: - url-and-parameters