New WAF Objects: [total: 12] ================================== Policy: name: "CVE-2026-56290: Page Builder CK fonts.save RCE" id: '20000381' minimum version: '10.0' predicates: - type: HTTP Request Method operation: At Least One values: - POST - type: HTTP Request operation: Match Any match values: - part: parameter name: url operation: includes value: http - part: parameter name: url operation: includes value: ftp - part: parameter name: filename operation: includes value: .ph - type: HTTP Request operation: Match All match values: - part: parameter name: task operation: MatchRegExp value: . - part: parameter name: option operation: includes value: com_pagebuilderck - part: url operation: includes value: index.php Policy: name: 'CVE-2026-48909: SP LMS PHP Object Injection' id: '20000380' minimum version: '10.0' predicates: - type: HTTP Request operation: Match All match values: - part: header name: cookie operation: includes value: lmsOrders - part: url operation: includes value: /index.php - part: parameter name: option operation: includes value: com_splms Signature: ID: '708575' Name: NoSQL $where + this.password Attack: SQL Injection - Blocking Attack Class: SQL Injection Dictionary: Recommended for Blocking for Web Applications Pattern: part="$where", part="this.password", rgxp="where=this\.password" Policy: Recommended Signatures Policy for Web Applications Search In: - parameters Signature: ID: '708574' Name: NoSQL $where + this.username Attack: SQL Injection - Blocking Attack Class: SQL Injection Dictionary: Recommended for Blocking for Web Applications Pattern: part="$where", part="this.username", rgxp="where=this\.username" Policy: Recommended Signatures Policy for Web Applications Search In: - parameters Signature: ID: '708573' Name: NoSQL $where + return Attack: SQL Injection - Blocking Attack Class: SQL Injection Dictionary: Recommended for Blocking for Web Applications Pattern: part="$where", part="return", rgxp="where=return" Policy: Recommended Signatures Policy for Web Applications Search In: - parameters Signature: ID: '708572' Name: NoSQL code + .$ Attack: SQL Injection - Blocking Attack Class: SQL Injection Dictionary: Recommended for Blocking for Web Applications Pattern: part="code\.\x24", rgxp="code\.\x24(?:ne|gt|gte|lt|lte|in|nin|exists|regex|where|eq)\s?=" Policy: Recommended Signatures Policy for Web Applications Search In: - parameters Signature: ID: '708571' Name: NoSQL password + .$ Attack: Directory Traversal Attack Class: Directory Traversal Dictionary: Recommended for Blocking for Web Applications Pattern: part="password\.\x24", rgxp="password\.\x24(?:ne|gt|gte|lt|lte|in|nin|exists|regex|where|eq)\s?=" Policy: Recommended Signatures Policy for Web Applications Search In: - parameters Signature: ID: '708570' Name: NoSQL username + .$ Attack: SQL Injection - Blocking Attack Class: SQL Injection Dictionary: Recommended for Blocking for Web Applications Pattern: part="username\.\x24", rgxp="username\.\x24(?:ne|gt|gte|lt|lte|in|nin|exists|regex|where|eq)\s?=" Policy: Recommended Signatures Policy for Web Applications Search In: - parameters Signature: ID: '708569' Name: NoSQL username [$ Attack: SQL Injection - Blocking Attack Class: SQL Injection Dictionary: Recommended for Blocking for Web Applications Pattern: part="username[$", rgxp="username\x5b\x24[\s\S]{1,15}=" Policy: Recommended Signatures Policy for Web Applications Search In: - parameters Signature: ID: '708568' Name: NoSQL password [$ Attack: SQL Injection - Blocking Attack Class: SQL Injection Dictionary: Recommended for Blocking for Web Applications Pattern: part="password[$", rgxp="password\x5b\x24[\s\S]{1,15}=" Policy: Recommended Signatures Policy for Web Applications Search In: - parameters Signature: ID: '708567' Name: LDAP using )(objectclass=top) Attack: Remote Command Execution - Blocking Attack Class: Remote Command Execution Dictionary: Recommended for Blocking for Web Applications Pattern: part=")(objectclass=top)" Policy: Recommended Signatures Policy for Web Applications Search In: - parameters - headers Policy: name: 'CVE-2026-8037: Progress Kemp LoadMaster - Uninitialized Heap to Pre-Auth RCE' id: '20000379' minimum version: '10.0' predicates: - type: HTTP Request Method operation: At Least One values: - POST - type: HTTP Request operation: Match All match values: - part: parameter name: apiuser operation: includes value: '''''''''' - part: url operation: includes value: /accessv2 - part: header name: Content-Type operation: includes value: application/json - part: parameter name: cmd operation: includes value: getall