<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/zero-trust-security/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T06:59:07.000Z</news:publication_date>
      <news:title>Understanding Zero Trust Security: Architecture and Network</news:title>
      <news:keywords>Security News</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-19418-typo3-backend-referrer-bypass-csrf-xss</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T21:50:49.252Z</news:publication_date>
      <news:title>CVE-2026-19418: TYPO3 CMS Backend Broken Referrer Enforcement Allows CSRF via XSS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59724-engine-io-webtransport-prototype-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T21:49:01.189Z</news:publication_date>
      <news:title>CVE-2026-59724: engine.io WebTransport Prototype Lookup DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-71415-kirby-cms-chunked-upload-missing-authorization</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T22:28:49.524Z</news:publication_date>
      <news:title>CVE-2026-71415: Kirby CMS Unauthenticated Chunked Upload Storage Exhaustion</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73086-nanoid-integer-overflow-csprng-pool-corruption</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T19:29:11.673Z</news:publication_date>
      <news:title>CVE-2026-73086: nanoid Integer Overflow Corrupts CSPRNG Pool</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-73089-browserslist-unbounded-cache-oom-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T16:49:06.476Z</news:publication_date>
      <news:title>CVE-2026-73089: browserslist Unbounded Cache Memory Exhaustion (DoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-78680-nltk-uncontrolled-search-path-graphviz-dot</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T20:51:31.034Z</news:publication_date>
      <news:title>CVE-2026-78680: NLTK Uncontrolled Search Path via Graphviz dot Binary</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-79675-nltk-jvm-argument-injection-per-call-options</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T20:49:02.002Z</news:publication_date>
      <news:title>CVE-2026-79675: NLTK JVM Argument Injection via Per-Call Options (Stanford Wrappers)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-81889-elfinder-ssrf-dns-rebinding-fsock</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T20:49:03.684Z</news:publication_date>
      <news:title>CVE-2026-81889: elFinder SSRF Protection Bypass via DNS Rebinding</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-84304-grpc-go-http2-data-frame-oom</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T21:49:17.387Z</news:publication_date>
      <news:title>CVE-2026-84304: gRPC-Go Heap Memory Exhaustion via HTTP/2 DATA Frame Fragmentation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/league-commonmark-attributesextension-form-feed-xss-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T20:29:50.909Z</news:publication_date>
      <news:title>league/commonmark AttributesExtension on* Filter Bypass via U+000C Form Feed (XSS)</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/mlflow-statsmodels-pickle-deserialization-bypass-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T17:08:59.428Z</news:publication_date>
      <news:title>mlflow statsmodels flavor MLFLOW_ALLOW_PICKLE_DESERIALIZATION bypass RCE</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/mysql2-auth-plugin-downgrade-cleartext-credential-leak</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T16:51:18.586Z</news:publication_date>
      <news:title>mysql2: Auth Plugin Downgrade Leaks Plaintext Credentials</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/pnpm-pacquet-trust-lockfile-dependency-alias-path-traversal</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T19:09:20.494Z</news:publication_date>
      <news:title>pnpm pacquet: Trust-Lockfile Dependency Alias Path Traversal</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/pnpm-workspace-yaml-proxy-env-secret-exfiltration</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T19:30:22.182Z</news:publication_date>
      <news:title>pnpm Environment Secret Exfiltration via Proxy Settings in pnpm-workspace.yaml</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
</urlset>