I discovered a bypass for KNOXSS WAF that allows an XSS attack by using the payload '</<K<Svg Onload=alert(1)>'. This payload exploits a vulnerability in the WAF's handling of SVG tags, allowing an attacker to execute arbitrary JavaScript code.
