<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/api-security-testing/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T11:54:25.000Z</news:publication_date>
      <news:title>Security Testing For API: Types, Best Tools, And Checklist</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/ai-powered-pentest-vs-ai-native-pentest/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T06:05:42.000Z</news:publication_date>
      <news:title>AI-Powered Pentest vs AI-Native Pentest: Key Differences</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/claude-faf-mcp-path-traversal-arbitrary-file-read-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19T20:17:35.837Z</news:publication_date>
      <news:title>claude-faf-mcp Arbitrary File Read/Write via Unconfined Path Argument</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53951-copier-trust-prefix-path-traversal-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19T20:16:21.297Z</news:publication_date>
      <news:title>CVE-2026-53951: copier Trust-Prefix Bypass via Path Traversal Leads to Arbitrary Command Execution</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53957-contentful-mcp-server-ssrf-host-proxy-pat-exfiltration</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19T20:04:50.783Z</news:publication_date>
      <news:title>CVE-2026-53957: @contentful/mcp-server SSRF via LLM-Controlled host/proxy Parameters</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53964-document-merge-service-xlsx-ssti-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19T20:11:48.937Z</news:publication_date>
      <news:title>CVE-2026-53964: document-merge-service Remote Code Execution via SSTI in XLSX Templates</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53965-mcp-sdk-httptransport-sse-buffer-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19T19:30:42.092Z</news:publication_date>
      <news:title>CVE-2026-53965: mcp/sdk HttpTransport Unbounded SSE Buffer Memory Exhaustion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53966-xwiki-livedata-livetable-missing-authorization-privilege-escalati</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19T19:37:41.404Z</news:publication_date>
      <news:title>CVE-2026-53966: XWiki Platform Live Data Live Table Connector Missing Authorization Privilege Escalation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54061-dgraph-streamextsnapshot-unauthenticated-store-wipe</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T17:49:44.806Z</news:publication_date>
      <news:title>CVE-2026-54061: Dgraph Alpha Unauthenticated Remote Group Store Wipe via StreamExtSnapshot</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54167-pipelines-as-code-github-app-jwt-exfiltration-enterprise-host-hea</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:31:01.063Z</news:publication_date>
      <news:title>CVE-2026-54167: Pipelines-as-Code GitHub App JWT Exfiltration via Untrusted X-GitHub-Enterprise-Host Header</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54175-backpack-crud-unverified-password-change-mass-assignment</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:28:48.686Z</news:publication_date>
      <news:title>CVE-2026-54175: Laravel Backpack CRUD Unverified Password Change via Mass Assignment</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54178-backpack-crud-arbitrary-file-deletion-upload-multiple</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:24:38.258Z</news:publication_date>
      <news:title>CVE-2026-54178: Backpack CRUD Arbitrary File Deletion via Unvalidated clear_&lt;attr&gt;[] Input</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54180-laravel-backpack-crud-idor-write-operations</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:23:21.216Z</news:publication_date>
      <news:title>CVE-2026-54180: Laravel Backpack CRUD Cross-Tenant IDOR on Write Operations</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54182-backpack-crud-os-command-injection-host-header</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:15:46.249Z</news:publication_date>
      <news:title>CVE-2026-54182: backpack/crud OS Command Injection via Host Header</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54245-fleetdm-okta-conditional-access-sql-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:04:54.111Z</news:publication_date>
      <news:title>CVE-2026-54245: Fleet SQL Injection in Okta Conditional Access Endpoint</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54251-netty-ohttp-direct-memory-leak-aead-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:03:38.781Z</news:publication_date>
      <news:title>CVE-2026-54251: netty-incubator-codec-ohttp Native Direct-Memory Leak on AEAD Decryption Failure</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54263-wagtail-reflected-xss-image-url-generator</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:21:57.257Z</news:publication_date>
      <news:title>CVE-2026-54263: Wagtail Reflected XSS in Dynamic Image URL Generator</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55149-vouch-proxy-multipart-cookie-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T17:28:44.276Z</news:publication_date>
      <news:title>CVE-2026-55149: vouch-proxy Unbounded Multipart Cookie Allocation DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61798-netty-ohttp-hpke-private-key-tostring-exposure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T18:56:05.986Z</news:publication_date>
      <news:title>CVE-2026-61798: netty-incubator-codec-ohttp BoringSSL HPKE Private Key Exposure via toString()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61827-netty-bhttp-parser-oom-variable-length</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T18:51:38.823Z</news:publication_date>
      <news:title>CVE-2026-61827: netty-incubator-codec-bhttp BinaryHttpParser Unbounded Memory Allocation (OOM)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62673-grav-htaccess-case-sensitivity-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19T19:42:07.303Z</news:publication_date>
      <news:title>CVE-2026-62673: Grav .htaccess File Extension Filter Case-Sensitivity Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63124-netty-bhttp-binaryhttpparser-infinite-loop-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T18:54:59.236Z</news:publication_date>
      <news:title>CVE-2026-63124: netty-incubator-codec-bhttp BinaryHttpParser Infinite Loop DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63188-logto-tunnel-path-traversal-static-file</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19T20:28:46.777Z</news:publication_date>
      <news:title>CVE-2026-63188: @logto/tunnel Path Traversal via Unsanitized request.url</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63202-netty-bhttp-binaryhttpparser-infinite-loop-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T18:49:59.829Z</news:publication_date>
      <news:title>CVE-2026-63202: netty-incubator-codec-bhttp BinaryHttpParser Infinite Loop DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/faf-mcp-path-traversal-arbitrary-file-read-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19T20:23:29.592Z</news:publication_date>
      <news:title>faf-mcp Arbitrary File Read/Write via Unconfined Path Argument</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/geolens-authorization-bypass-private-dataset-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19T20:10:28.571Z</news:publication_date>
      <news:title>GeoLens Authorization and Cache-Scope Flaws Disclose Private Dataset Data</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/grok-faf-mcp-arbitrary-file-read-unconfined-path</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-19T20:24:52.568Z</news:publication_date>
      <news:title>grok-faf-mcp: Arbitrary File Read via Unconfined Path in FAF Tools</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/nocobase-arbitrary-file-write-lfi-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T18:57:29.521Z</news:publication_date>
      <news:title>NocoBase: Arbitrary File Write and Local File Inclusion leading to Remote Code Execution</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/winter-cms-twig-sandbox-escape-eloquent-call-forwarding-cve-2024-54149-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T18:48:52.120Z</news:publication_date>
      <news:title>Winter CMS: Authenticated Twig Sandbox Escape via Eloquent __call Forwarding (Bypass of CVE-2024-54149)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>