<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-11745-centraldogma-ssh-host-key-mitm</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T20:49:10.532Z</news:publication_date>
      <news:title>CVE-2026-11745: centraldogma-server-mirror-git SSH Host Key Verification Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-11746-centraldogma-hardcoded-zookeeper-secret-cluster-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T20:50:30.535Z</news:publication_date>
      <news:title>CVE-2026-11746: Central Dogma Hard-coded ZooKeeper Replication Secret Enables Cluster Takeover</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56825-shopper-collection-products-missing-authorization</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:50:26.289Z</news:publication_date>
      <news:title>CVE-2026-56825: Shopper CollectionProducts Missing Authorization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56827-shopper-filament-bulk-action-missing-authorization</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:08:55.804Z</news:publication_date>
      <news:title>CVE-2026-56827: Shopper Framework Missing Authorization on Filament Bulk Actions</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56828-shopper-framework-livewire-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:54:58.838Z</news:publication_date>
      <news:title>CVE-2026-56828: shopper/framework Privilege Escalation via Livewire Misconfigured Authorization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56829-shopper-variantstock-missing-authorization-inventory-manipulation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:51:37.206Z</news:publication_date>
      <news:title>CVE-2026-56829: Shopper VariantStock Missing Authorization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59148-mockoon-unauthenticated-admin-api-csrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T22:09:15.823Z</news:publication_date>
      <news:title>CVE-2026-59148: @mockoon/commons-server Unauthenticated Admin API + Wildcard CORS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59151-prowler-saml-cross-tenant-account-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:49:20.475Z</news:publication_date>
      <news:title>CVE-2026-59151: Prowler SAML Cross-Tenant Account Takeover</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59960-argos-ci-core-branch-os-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T23:05:10.011Z</news:publication_date>
      <news:title>CVE-2026-59960: @argos-ci/core CI Branch Name OS Command Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59965-payload-alt-text-plugin-authorization-bypass-overrideaccess</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T22:57:41.306Z</news:publication_date>
      <news:title>CVE-2026-59965: @jhb.software/payload-alt-text-plugin Authorization Bypass via overrideAccess Omission</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59971-mysql-mcp-server-unauth-sql-execution-dns-rebinding</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T20:51:56.620Z</news:publication_date>
      <news:title>CVE-2026-59971: mysql-mcp-server Unauthenticated SQL Execution via Missing Origin and Host Validation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59973-mcp-from-openapi-ssrf-filter-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T22:10:28.749Z</news:publication_date>
      <news:title>CVE-2026-59973: mcp-from-openapi OpenAPI $ref SSRF Filter Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61534-yayson-prototype-pollution-jsonapi-store</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T22:28:51.427Z</news:publication_date>
      <news:title>CVE-2026-61534: yayson Prototype Pollution via JSON:API Type Deserialization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-87011-open-webui-backchannel-logout-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T23:03:55.015Z</news:publication_date>
      <news:title>CVE-2026-87011: open-webui OIDC Back-Channel Logout Unauthenticated DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-87016-open-webui-oauth-subject-wildcard-auth-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T21:29:01.615Z</news:publication_date>
      <news:title>CVE-2026-87016: Open WebUI OAuth Subject Wildcard Authentication Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88004-traefik-trailer-header-sanitization-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T23:10:23.458Z</news:publication_date>
      <news:title>CVE-2026-88004: Traefik Entrypoint Header Sanitization Bypass via HTTP Trailers</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88007-traefik-http3-ntlm-connection-reuse</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T23:11:35.952Z</news:publication_date>
      <news:title>CVE-2026-88007: Traefik HTTP/3 NTLM Backend Connection Reuse</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88008-traefik-h2c-upgrade-middleware-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T23:09:12.428Z</news:publication_date>
      <news:title>CVE-2026-88008: Traefik h2c Upgrade Middleware Bypass via HTTP Request Smuggling</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88009-traefik-opaque-request-target-routing-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T23:15:07.343Z</news:publication_date>
      <news:title>CVE-2026-88009: Traefik HTTP Request Smuggling via Rootless Opaque Request-Target</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88017-rclone-ftp-auth-proxy-cross-session-credential-overwrite</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T22:49:51.854Z</news:publication_date>
      <news:title>CVE-2026-88017: rclone FTP Auth-Proxy Cross-Session Credential Overwrite</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88018-rclone-serve-s3-sigv4-auth-bypass-empty-secret</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T23:02:20.476Z</news:publication_date>
      <news:title>CVE-2026-88018: rclone serve s3 SigV4 Authentication Bypass via Empty Secret</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88044-rclone-rc-auth-proxy-bypass-ftp-s3</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T22:55:44.464Z</news:publication_date>
      <news:title>CVE-2026-88044: rclone RC Per-Server Auth-Proxy Bypass (FTP/S3)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88045-rclone-serve-s3-multipart-memory-exhaustion</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T22:51:06.483Z</news:publication_date>
      <news:title>CVE-2026-88045: rclone serve s3 Multipart Memory Exhaustion via Declared Content-Length</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-88062-omniroute-acp-agent-unauthenticated-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T21:30:22.248Z</news:publication_date>
      <news:title>CVE-2026-88062: omniroute Unauthenticated Remote Code Execution via Custom ACP Agent</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/mistralrs-server-core-unbounded-media-fetch-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-10T22:08:56.939Z</news:publication_date>
      <news:title>mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>