<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/log4j2-marshalledobject-deserialization-bypass-to-rce/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-26T17:37:45.000Z</news:publication_date>
      <news:title>Log4j2 MarshalledObject Deserialization Bypass to RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/autonomous-penetration-testing-complete-guide-2026/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:45:36.000Z</news:publication_date>
      <news:title>Autonomous Penetration Testing: Complete Guide 2026</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-45018-chainlit-mcp-stdio-command-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T19:30:11.793Z</news:publication_date>
      <news:title>CVE-2026-45018: Chainlit Unauthenticated Remote Code Execution via MCP stdio Command Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-45019-chainlit-mcp-ssrf-internal-network</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T19:29:02.230Z</news:publication_date>
      <news:title>CVE-2026-45019: Chainlit SSRF via MCP SSE and Streamable-HTTP Transports</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-48853-elixir-grpc-erlpack-unsafe-deserialization-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:37:53.869Z</news:publication_date>
      <news:title>CVE-2026-48853: erlang/grpc Unsafe Deserialization Leading to RCE and DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-48854-elixir-grpc-unbounded-body-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:31:34.898Z</news:publication_date>
      <news:title>CVE-2026-48854: elixir-grpc Unbounded Request Body Memory Exhaustion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-49757-ash-authentication-oauth2-oidc-account-takeover-email-spoofing</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:29:04.496Z</news:publication_date>
      <news:title>CVE-2026-49757: ash_authentication OAuth2/OIDC Account Takeover via Email Spoofing</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53430-elixir-grpc-gzip-decompression-bomb-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:30:13.786Z</news:publication_date>
      <news:title>CVE-2026-53430: elixir-grpc Unbounded gzip Decompression Bomb (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54511-logtape-syslog-crlf-log-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-26T14:49:54.303Z</news:publication_date>
      <news:title>CVE-2026-54511: @logtape/syslog CRLF Log Injection via Unescaped C0 Control Characters</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54523-kyverno-namespacedmutatingpolicy-generator-apply-namespace-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-26T14:29:52.469Z</news:publication_date>
      <news:title>CVE-2026-54523: Kyverno NamespacedMutatingPolicy Missing Authorization in generator.apply()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54556-http4s-ember-hpack-bomb-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-26T14:31:24.780Z</news:publication_date>
      <news:title>CVE-2026-54556: http4s-ember-core HTTP/2 HPACK Bomb Denial of Service</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54563-cloudreve-webdav-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-26T15:30:05.907Z</news:publication_date>
      <news:title>CVE-2026-54563: Cloudreve WebDAV Scoped Credential Path Traversal</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54569-senaite-core-unauth-rce-eval-injection-jsonapi</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-26T15:50:24.986Z</news:publication_date>
      <news:title>CVE-2026-54569: senaite.core Unauthenticated Remote Code Execution via Eval Injection in JSON API</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54591-asyncssh-scp-path-traversal-arbitrary-file-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-26T15:49:03.822Z</news:publication_date>
      <news:title>CVE-2026-54591: asyncssh SCP Client Path Traversal to Arbitrary File Write</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54606-suneditor-embed-plugin-dom-xss-script-src</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-26T15:28:54.402Z</news:publication_date>
      <news:title>CVE-2026-54606: suneditor Embed Plugin DOM XSS via External Script Element</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55099-icalendar-component-equality-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T19:48:49.929Z</news:publication_date>
      <news:title>CVE-2026-55099: icalendar Algorithmic Complexity Denial of Service in Component Equality</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55596-platejs-media-embed-stored-xss-provider-metadata</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:48:48.260Z</news:publication_date>
      <news:title>CVE-2026-55596: @platejs/media Media Embed Stored XSS via Serialized Provider Metadata</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55604-deepseek-mcp-server-session-hijack</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:48:47.330Z</news:publication_date>
      <news:title>CVE-2026-55604: @arikusi/deepseek-mcp-server Cross-Session Authorization Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55620-eml-parser-dos-nested-parens-received-header</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:36:08.765Z</news:publication_date>
      <news:title>CVE-2026-55620: eml_parser ReDoS via Deeply Nested Parentheses in Received Headers</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55629-whistle-arbitrary-file-read-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:34:53.706Z</news:publication_date>
      <news:title>CVE-2026-55629: whistle Arbitrary File Read via Path Traversal</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55637-genieacs-mcp-dns-rebinding-origin-validation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T18:08:49.899Z</news:publication_date>
      <news:title>CVE-2026-55637: genieacs-mcp DNS Rebinding via Missing Host and Origin Validation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56777-phpmyfaq-group-permissions-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T17:50:34.647Z</news:publication_date>
      <news:title>CVE-2026-56777: phpMyFAQ GroupController Privilege Escalation via Missing Self-Rights Constraint</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-9769-justhtml-uncontrolled-recursion-dos-nested-html</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T16:50:51.995Z</news:publication_date>
      <news:title>CVE-2026-9769: justhtml Uncontrolled Recursion DoS via Deeply Nested HTML</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/librenms-stored-xss-snmp-syslog-legacy-templates</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-26T18:08:59.280Z</news:publication_date>
      <news:title>LibreNMS Stored XSS via Unescaped SNMP and Syslog Data in Legacy Templates</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/mcp-contextforge-gateway-ssti-jinja2-rce-prompt-service</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-25T17:48:45.446Z</news:publication_date>
      <news:title>mcp-contextforge-gateway Server-Side Template Injection (SSTI) leading to RCE</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>