<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/best-ptaas-platforms/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-09T14:28:31.000Z</news:publication_date>
      <news:title>10 Best PTaaS Platforms for Penetration Testing in 2026</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55416-pimcore-custom-reports-sql-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T19:28:53.283Z</news:publication_date>
      <news:title>CVE-2026-55416: Pimcore Custom Reports SQL Injection via Report Configuration Fields</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55864-geonetwork-sld-unauthenticated-ssrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-09T23:48:50.813Z</news:publication_date>
      <news:title>CVE-2026-55864: GeoNetwork Unauthenticated SSRF in SLD Tool</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59158-nuxt-ollama-api-key-ssr-exposure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:22:43.196Z</news:publication_date>
      <news:title>CVE-2026-59158: nuxt-ollama API Key Exposed in SSR HTML Payload</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59160-turbo-graph-unauthenticated-task-execution</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:21:50.099Z</news:publication_date>
      <news:title>CVE-2026-59160: @yeger/turbo-graph Unauthenticated Remote Task Execution</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59161-excelize-getrows-streaming-row-bound-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:49:48.816Z</news:publication_date>
      <news:title>CVE-2026-59161: Excelize GetRows Streaming Row-Bound Bypass Leads to Attacker-Controlled Memory Allocation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59172-joker-linter-local-code-execution</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:16:11.122Z</news:publication_date>
      <news:title>CVE-2026-59172: Joker Linter Project-Local Code Execution</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59176-functype-mcp-server-set-functype-version-package-alias-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:11:45.194Z</news:publication_date>
      <news:title>CVE-2026-59176: functype-mcp-server set_functype_version Package Alias RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59177-esphome-device-builder-unauthenticated-ingress-lan-access</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:10:37.328Z</news:publication_date>
      <news:title>CVE-2026-59177: esphome-device-builder Unauthenticated Dashboard Access via Unrestricted Ingress Bind</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59179-openhop-server-path-traversal-flow-id</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:09:24.252Z</news:publication_date>
      <news:title>CVE-2026-59179: @openhop/server Path Traversal in Flow ID File Operations</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59185-identrail-cross-tenant-idor-github-installation-id</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:15:05.162Z</news:publication_date>
      <news:title>CVE-2026-59185: Identrail Cross-Tenant IDOR via Unverified GitHub App installation_id</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69439-diasymreader-native-heap-buffer-overflow-portable-pdb</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-09T16:10:18.050Z</news:publication_date>
      <news:title>CVE-2026-69439: Microsoft.DiaSymReader.Native Heap-Based Buffer Overflow</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69439-diasymreader-native-heap-buffer-overflow-portable-pdb-1</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-09T16:16:02.596Z</news:publication_date>
      <news:title>CVE-2026-69439: Microsoft.DiaSymReader.Native Heap-Based Buffer Overflow (EoP)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69522-diasymreader-native-pdb-heap-buffer-overflow-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-09T16:08:52.161Z</news:publication_date>
      <news:title>CVE-2026-69522: Microsoft.DiaSymReader.Native Heap-based Buffer Overflow RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71328-diasymreader-native-msfz-pdb-heap-buffer-overflow</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-09T16:11:31.488Z</news:publication_date>
      <news:title>CVE-2026-71328: Microsoft.DiaSymReader.Native Heap Buffer Overflow via Malformed MSFZ PDB</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71328-diasymreader-native-pdb-heap-buffer-overflow</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-09T16:14:55.584Z</news:publication_date>
      <news:title>CVE-2026-71328: Microsoft.DiaSymReader.Native Heap-Based Buffer Overflow via Malformed Portable PDB</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-85730-smol-toml-infinite-loop-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-09T18:08:59.786Z</news:publication_date>
      <news:title>CVE-2026-85730: smol-toml Denial of Service via Infinite Loop in Parser</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-86075-n8n-oauth-registration-storage-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:31:13.334Z</news:publication_date>
      <news:title>CVE-2026-86075: n8n Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-86076-n8n-expression-sandbox-escape-sanitizer-rebinding</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:36:07.995Z</news:publication_date>
      <news:title>CVE-2026-86076: n8n Expression Sandbox Escape via Class-Field Sanitizer Rebinding</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-86081-n8n-redos-git-node-clone-path</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:29:55.133Z</news:publication_date>
      <news:title>CVE-2026-86081: n8n Regular Expression Denial of Service via Git Node Clone Path</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-86082-n8n-openai-model-search-ssrf-domain-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:41:55.218Z</news:publication_date>
      <news:title>CVE-2026-86082: n8n OpenAI Chat Model Node SSRF via Unguarded Model-Search Endpoint</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-86083-n8n-json-stringify-code-injection-sandbox-escape</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T20:49:11.403Z</news:publication_date>
      <news:title>CVE-2026-86083: n8n Expression Sandbox Escape via JSON.stringify Hijacking</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-87016-open-webui-oauth-subject-wildcard-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T21:29:01.615Z</news:publication_date>
      <news:title>CVE-2026-87016: Open WebUI OAuth Subject Wildcard Authentication Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-87995-open-webui-port-preview-same-origin-xss-account-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:37:25.814Z</news:publication_date>
      <news:title>CVE-2026-87995: Open WebUI Same-Origin XSS to Account Takeover via Terminal Port-Preview iframe</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-87996-open-webui-playwright-dns-rebinding-ssrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:43:14.791Z</news:publication_date>
      <news:title>CVE-2026-87996: open-webui DNS Rebinding SSRF in Playwright Web Loader</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-87999-open-webui-ssrf-azure-platform-channel</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:44:57.022Z</news:publication_date>
      <news:title>CVE-2026-87999: Open WebUI SSRF via Azure Platform Channel Address Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88017-rclone-ftp-auth-proxy-cross-session-credential-overwrite</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T22:49:51.854Z</news:publication_date>
      <news:title>CVE-2026-88017: rclone FTP Auth-Proxy Cross-Session Credential Overwrite</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88056-angular-platform-server-ssrf-unicode-whitespace</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T20:30:30.824Z</news:publication_date>
      <news:title>CVE-2026-88056: @angular/platform-server SSRF via Unicode Whitespace Trim Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88060-angular-platform-server-ssr-template-documentfragment-xss</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T20:29:10.394Z</news:publication_date>
      <news:title>CVE-2026-88060: @angular/platform-server SSR XSS via Unescaped Template Content Across DocumentFragment Boundaries</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88062-omniroute-acp-agent-unauthenticated-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T21:30:22.248Z</news:publication_date>
      <news:title>CVE-2026-88062: omniroute Unauthenticated Remote Code Execution via Custom ACP Agent</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/eigenpal-docx-editor-core-css-injection-print-xss-font-family</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T15:09:05.723Z</news:publication_date>
      <news:title>@eigenpal/docx-editor-core: CSS Injection and Print-Time XSS via Unescaped Font Name</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/komari-csrf-admin-rce-cookie-samesite</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T00:17:18.547Z</news:publication_date>
      <news:title>Komari: Management Interface CSRF Leading to Remote Code Execution</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/mistralrs-server-core-unbounded-media-fetch-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T22:08:56.939Z</news:publication_date>
      <news:title>mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>