<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/cve-2026-10520-ivanti-sentry-os-command-injection/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T14:09:45.000Z</news:publication_date>
      <news:title>CVE-2026-10520: OS Command Injection in Ivanti Sentry MICS API Enables Pre-Auth Root Shell</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/apple-mach-o-archive-parser-integer-underflow/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-07T11:29:02.000Z</news:publication_date>
      <news:title>Archive Entry::name() Integer Underflow — Out-of-Bounds Read, Denial of Service and Information Disclosure in Apple&amp;#8217;s mach_o Archive Parser (ld / libtool / ranlib)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-60004-gitea-diffpatch-git-hook-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T18:10:31.979Z</news:publication_date>
      <news:title>CVE-2026-60004: Gitea Remote Code Execution via diffpatch Git Hook Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-62384-nltk-framenet-symlink-sandbox-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T17:10:28.916Z</news:publication_date>
      <news:title>CVE-2026-62384: NLTK FramenetCorpusReader Symlink Sandbox Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63312-nltk-streambackedcorpusview-pathsec-bypass-file-read</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T15:49:36.700Z</news:publication_date>
      <news:title>CVE-2026-63312: NLTK StreamBackedCorpusView Arbitrary File Read via pathsec.ENFORCE Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69222-liquidjs-join-filter-memorylimit-bypass-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T18:30:36.143Z</news:publication_date>
      <news:title>CVE-2026-69222: LiquidJS join Filter memoryLimit Bypass (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70626-nltk-corpusreader-symlink-escape-file-read</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T15:29:25.193Z</news:publication_date>
      <news:title>CVE-2026-70626: NLTK CorpusReader Symlink Escape Arbitrary File Read</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-72789-siyuan-encrypted-notebook-publish-access-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T18:11:51.265Z</news:publication_date>
      <news:title>CVE-2026-72789: SiYuan Encrypted Notebook Publish Access Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73294-semaphore-git-url-argument-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T18:09:06.508Z</news:publication_date>
      <news:title>CVE-2026-73294: Semaphore UI OS Command Injection via git_url Argument Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-75595-netty-sni-mtls-bypass-fragmented-clienthello</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T18:29:21.895Z</news:publication_date>
      <news:title>CVE-2026-75595: Netty SslClientHelloHandler SNI mTLS Bypass via Fragmented TLS ClientHello</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-78675-gitpython-gitmodules-include-file-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T18:55:01.173Z</news:publication_date>
      <news:title>CVE-2026-78675: GitPython Local File Content Disclosure via .gitmodules [include] Directive</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-78676-gitpython-config-reserialize-rce-hookspath</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T18:50:50.316Z</news:publication_date>
      <news:title>CVE-2026-78676: GitPython Multi-line Config Value RCE via Unsafe Re-serialization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-78677-gitpython-clone-separate-git-dir-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T18:49:04.255Z</news:publication_date>
      <news:title>CVE-2026-78677: GitPython clone_from() Path Traversal via --separate-git-dir</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-78681-nltk-xml-entity-expansion-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T16:50:25.560Z</news:publication_date>
      <news:title>CVE-2026-78681: NLTK XML Entity Expansion (Billion Laughs) DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-78682-nltk-pathsec-ssrf-proxy-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T17:05:06.858Z</news:publication_date>
      <news:title>CVE-2026-78682: NLTK pathsec SSRF Protection Bypass via HTTP Proxy</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-78683-nltk-transitionparser-pickle-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T16:57:56.838Z</news:publication_date>
      <news:title>CVE-2026-78683: nltk Unsafe Pickle Deserialization in TransitionParser</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-79657-nltk-allowlist-pickle-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T16:55:21.024Z</news:publication_date>
      <news:title>CVE-2026-79657: nltk Allowlisted Pickle Loader Remote Code Execution</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-79674-nltk-corpus-reader-pathsec-sandbox-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T17:02:31.106Z</news:publication_date>
      <news:title>CVE-2026-79674: NLTK Corpus Reader Constructor pathsec Sandbox Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-79676-nltk-corpus-reader-symlink-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-08T17:09:11.511Z</news:publication_date>
      <news:title>CVE-2026-79676: NLTK Corpus Readers Symlink Path Traversal (pathsec Bypass)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
</urlset>