<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-11745-centraldogma-ssh-host-key-mitm</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T20:49:10.532Z</news:publication_date>
      <news:title>CVE-2026-11745: centraldogma-server-mirror-git SSH Host Key Verification Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-11746-centraldogma-hardcoded-zookeeper-secret-cluster-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T20:50:30.535Z</news:publication_date>
      <news:title>CVE-2026-11746: Central Dogma Hard-coded ZooKeeper Replication Secret Enables Cluster Takeover</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56825-shopper-collection-products-missing-authorization</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:50:26.289Z</news:publication_date>
      <news:title>CVE-2026-56825: Shopper CollectionProducts Missing Authorization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56827-shopper-filament-bulk-action-missing-authorization</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:08:55.804Z</news:publication_date>
      <news:title>CVE-2026-56827: Shopper Framework Missing Authorization on Filament Bulk Actions</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56828-shopper-framework-livewire-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:54:58.838Z</news:publication_date>
      <news:title>CVE-2026-56828: shopper/framework Privilege Escalation via Livewire Misconfigured Authorization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-56829-shopper-variantstock-missing-authorization-inventory-manipulation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:51:37.206Z</news:publication_date>
      <news:title>CVE-2026-56829: Shopper VariantStock Missing Authorization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59148-mockoon-unauthenticated-admin-api-csrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T22:09:15.823Z</news:publication_date>
      <news:title>CVE-2026-59148: @mockoon/commons-server Unauthenticated Admin API + Wildcard CORS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59151-prowler-saml-cross-tenant-account-takeover</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T21:49:20.475Z</news:publication_date>
      <news:title>CVE-2026-59151: Prowler SAML Cross-Tenant Account Takeover</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59971-mysql-mcp-server-unauth-sql-execution-dns-rebinding</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T20:51:56.620Z</news:publication_date>
      <news:title>CVE-2026-59971: mysql-mcp-server Unauthenticated SQL Execution via Missing Origin and Host Validation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-59973-mcp-from-openapi-ssrf-filter-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T22:10:28.749Z</news:publication_date>
      <news:title>CVE-2026-59973: mcp-from-openapi OpenAPI $ref SSRF Filter Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-61534-yayson-prototype-pollution-jsonapi-store</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-11T22:28:51.427Z</news:publication_date>
      <news:title>CVE-2026-61534: yayson Prototype Pollution via JSON:API Type Deserialization</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
</urlset>