New WAF Objects: [total: 9] ================================== Signature: ID: '708593' Name: 'CVE-2026-64638: WordPress Core - XSS2Shell' Attack: Cross-Site Scripting - Blocking Attack Class: Cross-Site Scripting Dictionary: Recommended for Blocking for Web Applications Pattern: part="/wp-login.php", part="log", rgxp="log\=<\s{1,}(div|button|abbr|img|area)" Policy: Recommended Signatures Policy for Web Applications Search In: - url-and-parameters Policy: name: 'CVE-2026-20253: Splunk Enterprise Pre-auth - Arbitrary File Write and Path Traversal' id: '20000390' minimum version: '10.0' predicates: - type: HTTP Request operation: Match All match values: - part: url operation: includes value: /v1/postgres/recovery/backup - type: HTTP Request operation: Match All match values: - part: header name: Content-Type operation: includes value: application/json - type: HTTP Request operation: Match All match values: - part: parameter name: backupFile operation: MatchRegExp value: (\.\.[\/|\\]|^\/|^[a-zA-Z]:[\/\\]) - type: HTTP Request Parameter Name operation: At Least One values: - backupFile - type: HTTP Request Method operation: At Least One values: - POST Policy: name: 'CVE-2026-20253: Splunk Enterprise Pre-auth RCE' id: '20000389' minimum version: '10.0' predicates: - type: HTTP Request operation: Match Any match values: - part: parameter name: database operation: includes value: :// - part: parameter name: database operation: includes value: '=' - type: HTTP Request operation: Match All match values: - part: header name: Content-Type operation: includes value: application/json - type: HTTP Request Method operation: At Least One values: - POST - type: HTTP Request operation: Match All match values: - part: url operation: includes value: /v1/postgres/recovery/backup Policy: name: 'CVE-2026-59726: Ruflo - Unauthenticated RCE via MCP Bridge' id: '20000388' minimum version: '10.0' predicates: - type: HTTP Request Method operation: At Least One values: - POST - type: HTTP Request Parameter Name operation: At Least One values: - params.arguments.command - type: HTTP Request operation: Match All match values: - part: parameter name: params.name operation: includes value: ruflo__terminal_execute - part: parameter name: method operation: includes value: tools/call - part: header name: Host operation: includes value: :3001 - part: url operation: includes value: /mcp Policy: name: 'CVE-2026-61511: vBulletin - Unauthenticated RCE' id: '20000387' minimum version: '10.0' predicates: - type: HTTP Request operation: Match All match values: - part: parameter name: pagenav[pagenumber] operation: includes value: ))^(( - part: parameter name: routestring operation: includes value: ajax/render/pagenav - type: HTTP Request Method operation: At Least One values: - POST Signature: ID: '708590' Name: 'CVE-2026-18072: WordPrwss Advanced Responsive Video Embedder - authentication bypass 2' Attack: Authentication Bypass - Blocking Attack Class: Authentication Bypass Dictionary: Recommended for Blocking for Web Applications Pattern: part="_wpm=35fe7057ffed92ff7bc5a0b90f302a77fb5843ad6c972294d68da0b0553b3900" Policy: Recommended Signatures Policy for Web Applications Search In: - parameters Signature: ID: '708589' Name: 'CVE-2026-18072: WordPrwss Advanced Responsive Video Embedder - authentication bypass' Attack: Authentication Bypass - Blocking Attack Class: Authentication Bypass Dictionary: Recommended for Blocking for Web Applications Pattern: part="_wplogin=35fe7057ffed92ff7bc5a0b90f302a77fb5843ad6c972294d68da0b0553b3900" Policy: Recommended Signatures Policy for Web Applications Search In: - parameters Signature: ID: '708588' Name: 'SQLi using PostgreSQL functions #2' Attack: SQL Injection - Blocking Attack Class: SQL Injection Dictionary: Recommended for Blocking for Web Applications Pattern: part="select", rgxp="[\'\"\`]\s?\;\s*select[\s\S]{0,200}from[\s\S]{1,10}(?:pg_user|pg_stat_activity|pg_shadow|pg_proc|pg_database|pg_roles)[\s\S]{0,200}(\*|\-\-|#)" Policy: Recommended Signatures Policy for Web Applications Search In: - url-and-parameters Signature: ID: '708587' Name: 'SQLi using PostgreSQL functions #1' Attack: SQL Injection - Blocking Attack Class: SQL Injection Dictionary: Recommended for Blocking for Web Applications Pattern: part="select", rgxp="[\'\"\`]\s?\;\s*select[\s\S]{0,200}(?:pg_ls_dir|lo_import|lo_export|loread|lo_open|lo_unlink|string_agg|array_agg|listagg|version|current_setting)\s?\([\s\S]{0,200}(\*|\-\-|#)" Policy: Recommended Signatures Policy for Web Applications Search In: - url-and-parameters Modified WAF Objects: [total: 1] ================================== Policy: name: 'CVE-2026-8037: Progress Kemp LoadMaster - Uninitialized Heap to Pre-Auth RCE' id: '20000379' minimum version: '10.0' predicates: - type: HTTP Request Method operation: At Least One values: - POST - type: HTTP Request operation: Match All match values: - part: parameter name: apiuser operation: includes value: "''''" - part: url operation: includes value: /accessv2 - part: header name: Content-Type operation: includes value: application/json - part: parameter name: cmd operation: includes value: getall