<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/cve-2026-16723-fastjson-1x-rce-analysis/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T14:18:11.000Z</news:publication_date>
      <news:title>CVE-2026-16723: The Class-Loader-as-Primitive Bug Pattern Returns — Fastison 1.x Pre-Auth RCE via @JSONType + jar:http</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/owasp-web-security-testing-guide-wstg/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T10:08:23.000Z</news:publication_date>
      <news:title>OWASP Web Security Testing Guide (WSTG) Explained</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/server-side-template-injection/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T06:41:25.000Z</news:publication_date>
      <news:title>Server-Side Template Injection: Attacks &amp;#038; Prevention</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/life-at-securelayer7-rohit-hatagale/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-03T14:19:58.000Z</news:publication_date>
      <news:title>Life at SecureLayer7: An Honest Review From the AI Team</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/remote-file-inclusion/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-03T11:11:55.000Z</news:publication_date>
      <news:title>Remote File Inclusion Explained: Attacks and Prevention</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-18446-fast-uri-backslash-authority-host-confusion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-03T19:29:41.455Z</news:publication_date>
      <news:title>CVE-2026-18446: fast-uri Host Confusion via Backslash Authority Introducer</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67354-guzzle-uri-fragment-referer-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T13:10:09.235Z</news:publication_date>
      <news:title>CVE-2026-67354: guzzlehttp/guzzle URI Fragment Disclosure via Referer Header</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67355-guzzle-host-only-cookie-scope-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T13:08:56.649Z</news:publication_date>
      <news:title>CVE-2026-67355: guzzlehttp/guzzle Host-Only Cookie Scope Bypass</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-68945-angular-httptransfercache-cache-key-ambiguity-state-poisoning</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-03T16:08:51.025Z</news:publication_date>
      <news:title>CVE-2026-68945: @angular/common HttpTransferCache Cache-Key Ambiguity Leads to State Poisoning</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69149-angular-platform-server-ssr-fallback-rawcontent-xss</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-03T16:30:07.397Z</news:publication_date>
      <news:title>CVE-2026-69149: @angular/platform-server SSR Fallback Raw-Content XSS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69151-angular-compiler-i18n-event-handler-xss</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-03T16:28:52.266Z</news:publication_date>
      <news:title>CVE-2026-69151: @angular/compiler i18n Event-Handler Attribute XSS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69152-brace-expansion-dos-intermediate-arrays</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-03T16:48:48.747Z</news:publication_date>
      <news:title>CVE-2026-69152: brace-expansion DoS via unbounded intermediate arrays</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69192-ip-address-address4-leading-zero-octal-ssrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-03T20:08:58.234Z</news:publication_date>
      <news:title>CVE-2026-69192: ip-address Address4 Leading-Zero Octet SSRF Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69240-sequelize-oracle-sql-injection-to-date-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-03T20:48:40.393Z</news:publication_date>
      <news:title>CVE-2026-69240: Sequelize SQL Injection via Oracle TO_DATE/TO_TIMESTAMP Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69244-aiohttp-oob-heap-read-c-response-parser</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-03T21:08:53.543Z</news:publication_date>
      <news:title>CVE-2026-69244: aiohttp Out-of-Bounds Heap Read in C HTTP Response Parser</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69246-guzzle-noncanonical-host-ssrf-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-03T21:31:36.499Z</news:publication_date>
      <news:title>CVE-2026-69246: Guzzle Noncanonical Host SSRF Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69247-cryptography-pkcs7-envelopeddata-bleichenbacher-oracle</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-03T21:30:19.205Z</news:publication_date>
      <news:title>CVE-2026-69247: cryptography PKCS#7 EnvelopedData Bleichenbacher Oracle</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69249-cryptography-exponential-chain-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-03T21:28:56.965Z</news:publication_date>
      <news:title>CVE-2026-69249: cryptography Exponential Certificate Chain DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69250-flowise-oauth2-refresh-ssrf-secret-exfiltration</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T14:28:58.827Z</news:publication_date>
      <news:title>CVE-2026-69250: Flowise Unauthenticated OAuth2 Refresh SSRF and Secret Exfiltration</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69252-flowise-missing-authorization-files-api-workspace-isolation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T15:08:45.051Z</news:publication_date>
      <news:title>CVE-2026-69252: Flowise Missing Authorization on File Management API</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69253-flowise-vm2-sandbox-escape-rce-moment-locale</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T15:29:06.962Z</news:publication_date>
      <news:title>CVE-2026-69253: Flowise vm2 Sandbox Escape to RCE via moment locale Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69254-flowise-nodevm-sandbox-escape-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T15:50:45.696Z</news:publication_date>
      <news:title>CVE-2026-69254: Flowise RCE via NodeVM Sandbox Escape in executeJavaScriptCode()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69256-flowise-csvagent-pickle-deserialization-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T15:48:52.160Z</news:publication_date>
      <news:title>CVE-2026-69256: flowise-components CSVAgent Pickle Deserialization Remote Code Execution</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69257-flowise-ssrf-ipv4-mapped-ipv6-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T16:11:21.950Z</news:publication_date>
      <news:title>CVE-2026-69257: Flowise SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69258-flowise-overrideconfig-property-injection-prediction-api</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T16:10:00.766Z</news:publication_date>
      <news:title>CVE-2026-69258: Flowise Unauthenticated Property Injection via Ungated overrideConfig Spread</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69259-flowise-sqlite-record-manager-rce-arbitrary-file-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T16:08:50.356Z</news:publication_date>
      <news:title>CVE-2026-69259: Flowise SQLite Record Manager Authenticated RCE via Arbitrary File Write</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
</urlset>