<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/owasp-top-10-proactive-controls/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T11:09:24.000Z</news:publication_date>
      <news:title>A Guide to OWASP Top 10 Proactive Controls</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/apache-dubbo-remote-003-path-traversal/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T14:38:03.000Z</news:publication_date>
      <news:title>REMOTE-003 Path Traversal in Configuration Subsystem of Apache Dubbo 3.3.x</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://blog.securelayer7.net/ai-security/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T11:13:15.000Z</news:publication_date>
      <news:title>AI Security: A Complete Guide to Securing Enterprise AI Systems</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53950-tryghost-activitypub-stored-xss</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T22:09:37.437Z</news:publication_date>
      <news:title>CVE-2026-53950: @tryghost/activitypub Stored XSS via Federated Post Content</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54572-rclone-links-symlink-escape-arbitrary-file-write</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T20:29:14.281Z</news:publication_date>
      <news:title>CVE-2026-54572: rclone Symlink Target Escape via --links (Arbitrary File Write)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54763-traefik-underscore-header-identity-spoofing</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T17:09:04.206Z</news:publication_date>
      <news:title>CVE-2026-54763: Traefik BasicAuth/DigestAuth/ForwardAuth Underscore Header Identity Spoofing</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59733-rclone-restic-private-repos-path-traversal-authz-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T20:48:57.512Z</news:publication_date>
      <news:title>CVE-2026-59733: rclone serve restic --private-repos Authorization Bypass via Path Traversal</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-65600-traefik-replacepathregex-auth-bypass-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T17:10:21.964Z</news:publication_date>
      <news:title>CVE-2026-65600: Traefik ReplacePathRegex Authentication Bypass via Path Traversal</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-67309-traefik-ingressnginx-rewritetarget-path-traversal-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T16:49:01.930Z</news:publication_date>
      <news:title>CVE-2026-67309: Traefik Kubernetes Ingress NGINX RewriteTarget Path Traversal Authentication Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-69264-flowise-csvagent-pyodide-code-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T17:49:01.092Z</news:publication_date>
      <news:title>CVE-2026-69264: Flowise CSVAgent Pyodide Code Injection RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70470-flowise-pyodide-unicode-homoglyph-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T17:56:26.478Z</news:publication_date>
      <news:title>CVE-2026-70470: Flowise Pyodide Validator Unicode Homoglyph Bypass RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70471-flowise-rbac-bypass-workspace-variables-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T17:51:28.799Z</news:publication_date>
      <news:title>CVE-2026-70471: Flowise RBAC Bypass Leading to Workspace Variables Disclosure</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70472-flowise-cross-workspace-credential-idor-openai-assistants</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T17:54:51.688Z</news:publication_date>
      <news:title>CVE-2026-70472: Flowise Cross-Workspace Credential IDOR in OpenAI Assistants Vector Store</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70473-flowise-upsert-history-information-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T18:09:33.242Z</news:publication_date>
      <news:title>CVE-2026-70473: Flowise Server-Wide Upsert History Information Disclosure</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70475-flowise-missing-authorization-execution-update</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T19:29:51.229Z</news:publication_date>
      <news:title>CVE-2026-70475: Flowise Missing Authorization on Execution Update Endpoint</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70476-flowise-stripe-subscription-idor-billing</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T19:28:46.981Z</news:publication_date>
      <news:title>CVE-2026-70476: Flowise Broken Access Control in Stripe Billing Endpoints</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70477-flowise-csv-agent-prompt-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T19:51:05.625Z</news:publication_date>
      <news:title>CVE-2026-70477: Flowise CSV Agent Prompt Injection Remote Code Execution</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70479-open-webui-playwright-ssrf-sub-resource</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T19:48:59.147Z</news:publication_date>
      <news:title>CVE-2026-70479: open-webui SSRF via Unvalidated Sub-Resource Requests in Playwright Web Loader</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70485-open-webui-nat64-ssrf-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T20:09:30.218Z</news:publication_date>
      <news:title>CVE-2026-70485: Open WebUI NAT64-Encoded SSRF Filter Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70492-open-webui-katex-stored-xss-render-error</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T21:09:39.744Z</news:publication_date>
      <news:title>CVE-2026-70492: open-webui Stored XSS via KaTeX Render-Error Fallback</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70601-electron-contextbridge-bind-hijack-context-isolation-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T15:49:56.860Z</news:publication_date>
      <news:title>CVE-2026-70601: Electron Context Isolation Bypass via Function.prototype.bind Hijack</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-70608-electron-sandboxed-iframe-allow-popups-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T17:48:54.554Z</news:publication_date>
      <news:title>CVE-2026-70608: Electron Sandboxed iframe allow-popups Restriction Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71309-rclone-serve-restic-path-traversal-root-escape</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T20:30:34.412Z</news:publication_date>
      <news:title>CVE-2026-71309: rclone serve restic Path Traversal Backend Root Escape</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71312-rclone-sftp-powershell-smartquote-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T20:50:14.348Z</news:publication_date>
      <news:title>CVE-2026-71312: rclone SFTP PowerShell Smart-Quote Filename OS Command Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71314-nuxt-island-vfor-oom-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T21:10:14.928Z</news:publication_date>
      <news:title>CVE-2026-71314: Nuxt Unauthenticated DoS via Unbounded v-for Expansion in Island Rendering</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71315-nuxt-approute-rules-mixedcase-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T21:08:47.270Z</news:publication_date>
      <news:title>CVE-2026-71315: Nuxt appMiddleware Auth Bypass via Mixed-Case Route Rule Keys</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71316-nuxt-payload-cache-cross-user-disclosure</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T21:28:54.256Z</news:publication_date>
      <news:title>CVE-2026-71316: Nuxt SSR Payload Cache Cross-User Information Disclosure</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71321-nuxt-island-cpu-exhaustion-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-05T21:48:52.115Z</news:publication_date>
      <news:title>CVE-2026-71321: Nuxt Island Endpoint Unauthenticated CPU Exhaustion (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71324-traefik-h2-connect-pool-poisoning-response-smuggling</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T16:09:05.929Z</news:publication_date>
      <news:title>CVE-2026-71324: Traefik HTTP/2 CONNECT Pool Poisoning Cross-User Response Smuggling</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71327-traefik-gateway-api-route-identity-collision</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-06T16:50:29.405Z</news:publication_date>
      <news:title>CVE-2026-71327: Traefik Gateway API Route Identity Collision Allows Cross-Namespace Backend Hijacking</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/flowise-s3-directory-loader-arbitrary-file-write-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-04T17:50:17.533Z</news:publication_date>
      <news:title>Flowise: Authenticated Arbitrary File Write via S3 Directory Loader Path Traversal</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>