<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/api-security-testing/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T11:54:25.000Z</news:publication_date>
      <news:title>Security Testing For API: Types, Best Tools, And Checklist</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/ai-powered-pentest-vs-ai-native-pentest/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T06:05:42.000Z</news:publication_date>
      <news:title>AI-Powered Pentest vs AI-Native Pentest: Key Differences</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54061-dgraph-streamextsnapshot-unauthenticated-store-wipe</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T17:49:44.806Z</news:publication_date>
      <news:title>CVE-2026-54061: Dgraph Alpha Unauthenticated Remote Group Store Wipe via StreamExtSnapshot</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54167-pipelines-as-code-github-app-jwt-exfiltration-enterprise-host-hea</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:31:01.063Z</news:publication_date>
      <news:title>CVE-2026-54167: Pipelines-as-Code GitHub App JWT Exfiltration via Untrusted X-GitHub-Enterprise-Host Header</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54175-backpack-crud-unverified-password-change-mass-assignment</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:28:48.686Z</news:publication_date>
      <news:title>CVE-2026-54175: Laravel Backpack CRUD Unverified Password Change via Mass Assignment</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54178-backpack-crud-arbitrary-file-deletion-upload-multiple</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:24:38.258Z</news:publication_date>
      <news:title>CVE-2026-54178: Backpack CRUD Arbitrary File Deletion via Unvalidated clear_&lt;attr&gt;[] Input</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54180-laravel-backpack-crud-idor-write-operations</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:23:21.216Z</news:publication_date>
      <news:title>CVE-2026-54180: Laravel Backpack CRUD Cross-Tenant IDOR on Write Operations</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54182-backpack-crud-os-command-injection-host-header</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:15:46.249Z</news:publication_date>
      <news:title>CVE-2026-54182: backpack/crud OS Command Injection via Host Header</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54245-fleetdm-okta-conditional-access-sql-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:04:54.111Z</news:publication_date>
      <news:title>CVE-2026-54245: Fleet SQL Injection in Okta Conditional Access Endpoint</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54251-netty-ohttp-direct-memory-leak-aead-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:03:38.781Z</news:publication_date>
      <news:title>CVE-2026-54251: netty-incubator-codec-ohttp Native Direct-Memory Leak on AEAD Decryption Failure</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54263-wagtail-reflected-xss-image-url-generator</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T19:21:57.257Z</news:publication_date>
      <news:title>CVE-2026-54263: Wagtail Reflected XSS in Dynamic Image URL Generator</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55149-vouch-proxy-multipart-cookie-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T17:28:44.276Z</news:publication_date>
      <news:title>CVE-2026-55149: vouch-proxy Unbounded Multipart Cookie Allocation DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59989-phalcon-volt-join-filter-code-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:28:49.288Z</news:publication_date>
      <news:title>CVE-2026-59989: Phalcon Volt Compiler join Filter PHP Code Injection (RCE)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61539-xinference-eval-injection-llama3-tool-parser-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:21:36.323Z</news:publication_date>
      <news:title>CVE-2026-61539: Xinference Remote Code Execution via Unsafe eval() in Llama3 Tool-Call Parser</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61798-netty-ohttp-hpke-private-key-tostring-exposure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T18:56:05.986Z</news:publication_date>
      <news:title>CVE-2026-61798: netty-incubator-codec-ohttp BoringSSL HPKE Private Key Exposure via toString()</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61827-netty-bhttp-parser-oom-variable-length</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T18:51:38.823Z</news:publication_date>
      <news:title>CVE-2026-61827: netty-incubator-codec-bhttp BinaryHttpParser Unbounded Memory Allocation (OOM)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63124-netty-bhttp-binaryhttpparser-infinite-loop-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T18:54:59.236Z</news:publication_date>
      <news:title>CVE-2026-63124: netty-incubator-codec-bhttp BinaryHttpParser Infinite Loop DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63135-yourls-stored-xss-referer-statistics-chart</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:14:56.252Z</news:publication_date>
      <news:title>CVE-2026-63135: YOURLS Stored XSS via Crafted Referer Header in Statistics Chart</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63202-netty-bhttp-binaryhttpparser-infinite-loop-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T18:49:59.829Z</news:publication_date>
      <news:title>CVE-2026-63202: netty-incubator-codec-bhttp BinaryHttpParser Infinite Loop DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63421-keystone-graphql-maxtake-negative-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:30:01.913Z</news:publication_date>
      <news:title>CVE-2026-63421: @keystone-6/core graphql.maxTake Bypass via Negative take</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-63462-unleash-server-dos-recursive-json-stringify</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T19:28:56.085Z</news:publication_date>
      <news:title>CVE-2026-63462: unleash-server Unauthenticated DoS via Recursive JSON Serialization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-64679-atlantis-workspace-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:24:48.031Z</news:publication_date>
      <news:title>CVE-2026-64679: Atlantis Workspace Path Traversal Allows Out-of-Bounds Directory Operations</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-68508-hydra-core-instantiate-code-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:11:32.435Z</news:publication_date>
      <news:title>CVE-2026-68508: hydra-core Unsafe Instantiation Code Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-76904-geotools-postgis-jsonarraycontains-sql-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T20:29:07.192Z</news:publication_date>
      <news:title>CVE-2026-76904: GeoTools gt-jdbc-postgis Unauthenticated SQL Injection via jsonArrayContains</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-76905-kin-openapi-multipart-nil-pointer-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:23:42.998Z</news:publication_date>
      <news:title>CVE-2026-76905: kin-openapi openapi3filter Nil-Pointer Panic via Malformed multipart/form-data</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-77354-kin-openapi-deepobject-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:17:17.937Z</news:publication_date>
      <news:title>CVE-2026-77354: kin-openapi Uncontrolled Memory Allocation via deepObject Query Parameter</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-77413-jsonata-arbitrary-code-execution-prototype-lookup</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:15:58.897Z</news:publication_date>
      <news:title>CVE-2026-77413: jsonata Arbitrary Code Execution via Prototype Chain Escape</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-77414-jsonata-code-injection-hasownproperty-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:10:16.473Z</news:publication_date>
      <news:title>CVE-2026-77414: jsonata Arbitrary Code Execution via hasOwnProperty Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-77415-jsonata-code-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-21T21:09:07.907Z</news:publication_date>
      <news:title>CVE-2026-77415: jsonata Arbitrary Code Execution via Crafted Expression</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/nocobase-arbitrary-file-write-lfi-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T18:57:29.521Z</news:publication_date>
      <news:title>NocoBase: Arbitrary File Write and Local File Inclusion leading to Remote Code Execution</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/winter-cms-twig-sandbox-escape-eloquent-call-forwarding-cve-2024-54149-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-20T18:48:52.120Z</news:publication_date>
      <news:title>Winter CMS: Authenticated Twig Sandbox Escape via Eloquent __call Forwarding (Bypass of CVE-2024-54149)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>