<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55175-spinnaker-rosco-kustomize-yaml-deserialization-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T18:57:47.040Z</news:publication_date>
      <news:title>CVE-2026-55175: Spinnaker rosco-manifests Unsafe YAML Deserialization RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55207-pimcore-studio-backend-password-reset-url-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:14:53.724Z</news:publication_date>
      <news:title>CVE-2026-55207: Pimcore Studio Backend Bundle Account Takeover via Password Reset URL Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55208-pimcore-studio-backend-datefilter-sql-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:09:51.900Z</news:publication_date>
      <news:title>CVE-2026-55208: Pimcore Studio Backend Bundle SQL Injection via DateFilter Column Key</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55212-pimcore-studio-backend-privilege-escalation-class-definition</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:08:43.896Z</news:publication_date>
      <news:title>CVE-2026-55212: Pimcore Studio Backend Bundle Privilege Escalation via Incorrect Permission Guard on Class Definition Creation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55215-mariadb-nodejs-ssl-mitm-password-leak</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:11:46.090Z</news:publication_date>
      <news:title>CVE-2026-55215: mariadb (npm) Cleartext Password Leak to MitM via Late SSL Fingerprint Check</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55228-weblate-groupviewset-idor-private-project</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T18:55:33.640Z</news:publication_date>
      <news:title>CVE-2026-55228: Weblate GroupViewSet IDOR Allows Unauthorized Private Project Access</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55245-bifrost-ispublicip-ssrf-nat64-cgnat-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T18:29:05.330Z</news:publication_date>
      <news:title>CVE-2026-55245: Bifrost isPublicIP SSRF Deny-List Bypass via NAT64, 6to4, and CGNAT</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55247-plone-app-event-ical-import-dos-ssrf-xss</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:16:13.642Z</news:publication_date>
      <news:title>CVE-2026-55247: plone.app.event iCalendar Import DoS, SSRF, and Stored XSS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55248-plone-app-portlets-rss-portlet-dos-ssrf-xss</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T18:50:36.444Z</news:publication_date>
      <news:title>CVE-2026-55248: plone.app.portlets RSS Portlet DoS, SSRF, and Stored XSS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55484-alos-http-malformed-path-dos-panic</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:21:44.595Z</news:publication_date>
      <news:title>CVE-2026-55484: alos-http Unauthenticated Remote Denial of Service via Malformed Path</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55520-protego-redos-robots-txt-wildcard</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T18:49:07.472Z</news:publication_date>
      <news:title>CVE-2026-55520: Protego ReDoS via robots.txt Wildcard Directive</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55584-phpsysinfo-ip-allowlist-bypass-x-forwarded-for</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:35:27.782Z</news:publication_date>
      <news:title>CVE-2026-55584: phpSysInfo IP Allowlist Bypass via Spoofed Headers</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55621-incus-custom-volume-copy-project-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:17:18.715Z</news:publication_date>
      <news:title>CVE-2026-55621: Incus Project Restriction Bypass via Custom Volume Copy</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55622-incus-instance-copy-project-restriction-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:02:31.853Z</news:publication_date>
      <news:title>CVE-2026-55622: Incus Project Restriction Bypass in Instance Copy</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55634-pimcore-dataobject-field-name-rce-sqli</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:23:08.779Z</news:publication_date>
      <news:title>CVE-2026-55634: Pimcore DataObject Field Name Remote Code Execution and SQL Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55638-9router-codex-rewrite-authorization-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:31:17.141Z</news:publication_date>
      <news:title>CVE-2026-55638: 9router Unauthenticated LLM Proxy Access via /codex Rewrite Authorization Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55641-9router-host-header-auth-bypass-ssrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:30:02.652Z</news:publication_date>
      <news:title>CVE-2026-55641: 9router Authentication Bypass via Host Header Spoofing and SSRF</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55673-powsybl-local-command-executor-os-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:04:19.574Z</news:publication_date>
      <news:title>CVE-2026-55673: powsybl-computation-local OS Command Injection via LocalCommandExecutor</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55761-portainer-unauthenticated-admin-takeover-init-restore</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T20:49:02.506Z</news:publication_date>
      <news:title>CVE-2026-55761: Portainer Unauthenticated Admin Takeover via Initialization Endpoints</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55764-klever-go-sft-int64-overflow-maxsupply-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T22:34:54.499Z</news:publication_date>
      <news:title>CVE-2026-55764: klever-go SFT Add-Quantity int64 Overflow Bypasses Per-Nonce MaxSupply</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55784-free5gc-ausf-auth-context-race-condition</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T22:29:06.226Z</news:publication_date>
      <news:title>CVE-2026-55784: free5GC AUSF Authentication Context Race Condition</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55830-restrictedpython-guard-hook-shadow-positional-only-args</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T23:09:01.854Z</news:publication_date>
      <news:title>CVE-2026-55830: RestrictedPython Guard Hook Shadow via Positional-Only Arguments</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55841-graylog-fortigate-syslog-field-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T22:31:19.930Z</news:publication_date>
      <news:title>CVE-2026-55841: Graylog FortiGate Syslog Parser Field Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55848-mapfish-print-xxe-gml-layer</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T22:49:40.195Z</news:publication_date>
      <news:title>CVE-2026-55848: MapFish Print XXE via GML Layer URL</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55874-seaweedfs-s3-copy-source-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T22:30:09.639Z</news:publication_date>
      <news:title>CVE-2026-55874: SeaweedFS S3 Gateway Cross-Bucket Path Traversal via X-Amz-Copy-Source</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
</urlset>