<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-35219-budibase-server-ssrf-automation-steps-blacklist-bypass</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T19:36:21.810Z</news:publication_date>
      <news:title>CVE-2026-35219: Budibase Server SSRF via Automation Steps Bypassing IP Blacklist</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-35511-authorizer-oauth-account-takeover-unverified-email-linking</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T15:48:49.798Z</news:publication_date>
      <news:title>CVE-2026-35511: Authorizer Zero-Click Account Takeover via OAuth Identity Linking</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53653-grav-image-resize-dos-unbounded-dimensions</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T19:31:34.572Z</news:publication_date>
      <news:title>CVE-2026-53653: Grav Unauthenticated DoS via Unbounded Image Resize Dimensions</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53657-lima-qemu-guest-agent-socket-privilege-escalation</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T19:30:13.133Z</news:publication_date>
      <news:title>CVE-2026-53657: Lima QEMU Guest Agent Socket World-Writable Privilege Escalation</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-53660-openam-sso-cookie-httponly-samesite-missing</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T19:28:53.225Z</news:publication_date>
      <news:title>CVE-2026-53660: OpenAM Insecure SSO Cookie Initialization (Missing HttpOnly and SameSite)</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55153-mchange-commons-java-unsafe-reflection-jndi-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T19:35:04.102Z</news:publication_date>
      <news:title>CVE-2026-55153: mchange-commons-java Unsafe Reflection via JavaBeanObjectFactory</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://securelayer7.net/lab/cve-2026-55157-token-optimizer-mcp-smart-user-command-injection</loc>
    <news:news>
      <news:publication>
        <news:name>SecureLayer7</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-14T21:48:51.497Z</news:publication_date>
      <news:title>CVE-2026-55157: @ooples/token-optimizer-mcp OS Command Injection via smart_user username</news:title>
      <news:keywords>CVE Advisory</news:keywords>
    </news:news>
  </url>
</urlset>