<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://blog.securelayer7.net/cve-2026-63077-teamcity-rce/</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T10:46:12.000Z</news:publication_date>
      <news:title>CVE-2026-63077: XStream Deserialization in JetBrains TeamCity&amp;#8217;s Agent Polling Protocol Enables Pre-Auth RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/crossplane-xpkg-cachedclient-toctou-signature-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-27T17:28:58.492Z</news:publication_date>
      <news:title>Crossplane xpkg.CachedClient TOCTOU Signature Verification Bypass</news:title>
      <news:keywords>Security Research</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54736-phalcon-crypt-decrypt-hmac-timing-side-channel</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T16:10:43.861Z</news:publication_date>
      <news:title>CVE-2026-54736: Phalcon Crypt::decrypt HMAC Timing Side-Channel</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54754-klever-go-marketplace-royalty-referral-klv-mint</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T16:31:01.279Z</news:publication_date>
      <news:title>CVE-2026-54754: klever-go Marketplace Settlement Integer Underflow Mints KLV</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54755-klever-go-split-royalty-integer-overflow-klv-mint</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T16:29:23.140Z</news:publication_date>
      <news:title>CVE-2026-54755: klever-go Integer Overflow in Split-Royalty Validation Enables Unbounded KLV Minting</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54757-compliance-trestle-ssti-markdown-include</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T16:34:54.429Z</news:publication_date>
      <news:title>CVE-2026-54757: compliance-trestle Server-Side Template Injection via Markdown Include Tags</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-54788-datadog-opentelemetry-tracestate-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T16:49:00.694Z</news:publication_date>
      <news:title>CVE-2026-54788: datadog-opentelemetry Unbounded tracestate Parsing DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55066-vikunja-kanban-idor-task-bucket</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T17:11:14.717Z</news:publication_date>
      <news:title>CVE-2026-55066: Vikunja Kanban Move-Task IDOR (Cross-Tenant Task Read and Write)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55108-kubevela-terraform-remote-symlink-dos</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T16:36:18.132Z</news:publication_date>
      <news:title>CVE-2026-55108: KubeVela Terraform Remote Loader Symlink DoS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55175-spinnaker-rosco-kustomize-yaml-deserialization-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T18:57:47.040Z</news:publication_date>
      <news:title>CVE-2026-55175: Spinnaker rosco-manifests Unsafe YAML Deserialization RCE</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55207-pimcore-studio-backend-password-reset-url-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:14:53.724Z</news:publication_date>
      <news:title>CVE-2026-55207: Pimcore Studio Backend Bundle Account Takeover via Password Reset URL Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55208-pimcore-studio-backend-datefilter-sql-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:09:51.900Z</news:publication_date>
      <news:title>CVE-2026-55208: Pimcore Studio Backend Bundle SQL Injection via DateFilter Column Key</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55212-pimcore-studio-backend-privilege-escalation-class-definition</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:08:43.896Z</news:publication_date>
      <news:title>CVE-2026-55212: Pimcore Studio Backend Bundle Privilege Escalation via Incorrect Permission Guard on Class Definition Creation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55215-mariadb-nodejs-ssl-mitm-password-leak</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:11:46.090Z</news:publication_date>
      <news:title>CVE-2026-55215: mariadb (npm) Cleartext Password Leak to MitM via Late SSL Fingerprint Check</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55228-weblate-groupviewset-idor-private-project</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T18:55:33.640Z</news:publication_date>
      <news:title>CVE-2026-55228: Weblate GroupViewSet IDOR Allows Unauthorized Private Project Access</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55245-bifrost-ispublicip-ssrf-nat64-cgnat-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T18:29:05.330Z</news:publication_date>
      <news:title>CVE-2026-55245: Bifrost isPublicIP SSRF Deny-List Bypass via NAT64, 6to4, and CGNAT</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55247-plone-app-event-ical-import-dos-ssrf-xss</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:16:13.642Z</news:publication_date>
      <news:title>CVE-2026-55247: plone.app.event iCalendar Import DoS, SSRF, and Stored XSS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55248-plone-app-portlets-rss-portlet-dos-ssrf-xss</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T18:50:36.444Z</news:publication_date>
      <news:title>CVE-2026-55248: plone.app.portlets RSS Portlet DoS, SSRF, and Stored XSS</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55460-snipe-it-bulk-user-delete-authorization-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T18:10:32.712Z</news:publication_date>
      <news:title>CVE-2026-55460: Snipe-IT Authorization Bypass on Bulk User Delete</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55484-alos-http-malformed-path-dos-panic</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:21:44.595Z</news:publication_date>
      <news:title>CVE-2026-55484: alos-http Unauthenticated Remote Denial of Service via Malformed Path</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55511-yamcs-streamsql-aggregate-column-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T17:09:14.349Z</news:publication_date>
      <news:title>CVE-2026-55511: yamcs-core Authenticated RCE via StreamSQL Aggregate Column-Name Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55516-snipe-it-maintenance-asset-id-authorization-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T18:08:48.316Z</news:publication_date>
      <news:title>CVE-2026-55516: Snipe-IT Cross-Company Asset Maintenance Re-Parenting via API</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55520-protego-redos-robots-txt-wildcard</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T18:49:07.472Z</news:publication_date>
      <news:title>CVE-2026-55520: Protego ReDoS via robots.txt Wildcard Directive</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55521-yamcs-core-api-missing-authorization</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T17:31:13.386Z</news:publication_date>
      <news:title>CVE-2026-55521: Yamcs Core API Multiple Missing Authorization Checks</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55552-yamcs-unauthenticated-directory-traversal-double-slash</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T17:30:01.007Z</news:publication_date>
      <news:title>CVE-2026-55552: Yamcs Unauthenticated Directory Traversal via Double-Slash URI</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55559-yamcs-core-template-yaml-injection-rce</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T17:28:53.535Z</news:publication_date>
      <news:title>CVE-2026-55559: yamcs-core Remote Code Execution via Instance Template YAML Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55584-phpsysinfo-ip-allowlist-bypass-x-forwarded-for</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:35:27.782Z</news:publication_date>
      <news:title>CVE-2026-55584: phpSysInfo IP Allowlist Bypass via Spoofed Headers</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55621-incus-custom-volume-copy-project-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:17:18.715Z</news:publication_date>
      <news:title>CVE-2026-55621: Incus Project Restriction Bypass via Custom Volume Copy</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55622-incus-instance-copy-project-restriction-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:02:31.853Z</news:publication_date>
      <news:title>CVE-2026-55622: Incus Project Restriction Bypass in Instance Copy</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55634-pimcore-dataobject-field-name-rce-sqli</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:23:08.779Z</news:publication_date>
      <news:title>CVE-2026-55634: Pimcore DataObject Field Name Remote Code Execution and SQL Injection</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55638-9router-codex-rewrite-authorization-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:31:17.141Z</news:publication_date>
      <news:title>CVE-2026-55638: 9router Unauthenticated LLM Proxy Access via /codex Rewrite Authorization Bypass</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55641-9router-host-header-auth-bypass-ssrf</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:30:02.652Z</news:publication_date>
      <news:title>CVE-2026-55641: 9router Authentication Bypass via Host Header Spoofing and SSRF</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55673-powsybl-local-command-executor-os-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T19:04:19.574Z</news:publication_date>
      <news:title>CVE-2026-55673: powsybl-computation-local OS Command Injection via LocalCommandExecutor</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55761-portainer-unauthenticated-admin-takeover-init-restore</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T20:49:02.506Z</news:publication_date>
      <news:title>CVE-2026-55761: Portainer Unauthenticated Admin Takeover via Initialization Endpoints</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-57584-phalcon-router-redos-catastrophic-backtracking</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-28T16:09:04.939Z</news:publication_date>
      <news:title>CVE-2026-57584: Phalcon Router Catastrophic Backtracking (ReDoS)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
</urlset>