<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/red-team-assessment-providers/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T10:06:24.000Z</news:publication_date>
      <news:title>The 14 Best Red Team Assessment Providers in 2026</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56668-zitadel-token-exchange-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-14T21:49:07.385Z</news:publication_date>
      <news:title>CVE-2026-56668: ZITADEL OAuth2 Token Exchange Missing Authorization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59178-esphome-device-builder-auth-bypass-env-rename</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-14T18:29:01.320Z</news:publication_date>
      <news:title>CVE-2026-59178: esphome-device-builder Silent Authentication Bypass on Upgrade</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61544-libp2p-quic-certificate-expiry-panic-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:14:54.826Z</news:publication_date>
      <news:title>CVE-2026-61544: libp2p-quic Remote Panic via Certificate Expiry Race</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61559-mcp-gitlab-ssrf-header-credential-theft</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T21:08:58.346Z</news:publication_date>
      <news:title>CVE-2026-61559: @zereight/mcp-gitlab Server-Side Request Forgery via X-GitLab-API-URL Header</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61568-mcp-gitlab-dns-rebinding-host-origin</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T21:10:18.299Z</news:publication_date>
      <news:title>CVE-2026-61568: @zereight/mcp-gitlab DNS Rebinding via Missing Host/Origin Validation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69202-http4s-ember-http2-unbounded-inbound-body-buffering</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:30:19.319Z</news:publication_date>
      <news:title>CVE-2026-69202: http4s Ember HTTP/2 Unbounded Inbound Body Buffering DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69203-http4s-ember-http2-max-concurrent-streams-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:29:02.307Z</news:publication_date>
      <news:title>CVE-2026-69203: http4s Ember HTTP/2 Unbounded Stream Allocation DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69204-http4s-ember-clte-request-smuggling</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:24:19.434Z</news:publication_date>
      <news:title>CVE-2026-69204: http4s Ember CL.TE HTTP Request Smuggling</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69205-http4s-ember-transfer-encoding-smuggling</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:23:10.603Z</news:publication_date>
      <news:title>CVE-2026-69205: http4s Ember Transfer-Encoding Case-Sensitive Parsing HTTP Request Smuggling</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69208-http4s-digestauth-nonce-map-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:21:51.134Z</news:publication_date>
      <news:title>CVE-2026-69208: http4s DigestAuth Nonce Map Unbounded Growth (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69213-http4s-ember-http2-unbounded-outbound-frame-queue</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:16:14.370Z</news:publication_date>
      <news:title>CVE-2026-69213: http4s Ember HTTP/2 Unbounded Outbound Frame Queue DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69218-http4s-ember-http2-continuation-flood-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:12:09.190Z</news:publication_date>
      <news:title>CVE-2026-69218: http4s Ember HTTP/2 Unbounded CONTINUATION Frame Memory Exhaustion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88975-http4s-ember-http2-frame-size-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T20:09:15.789Z</news:publication_date>
      <news:title>CVE-2026-88975: http4s Ember HTTP/2 Frame Size Memory Exhaustion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/mcp-gitlab-graphql-read-only-bypass-unauth-transport-session-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-15T21:15:15.819Z</news:publication_date>
      <news:title>@zereight/mcp-gitlab: GraphQL Read-Only Bypass, Unauthenticated Transports, and Session-Exhaustion DoS</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>