<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://sec.kaitan.id</loc>
<changefreq>daily</changefreq>
<priority>1</priority>
</url>
<url>
<loc>https://sec.kaitan.id/plans</loc>
<changefreq>monthly</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://sec.kaitan.id/cves</loc>
<changefreq>daily</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://sec.kaitan.id/exploits</loc>
<changefreq>daily</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/threats</loc>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/news</loc>
<changefreq>daily</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog</loc>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://sec.kaitan.id/about</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://sec.kaitan.id/services</loc>
<changefreq>monthly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://sec.kaitan.id/contact</loc>
<changefreq>monthly</changefreq>
<priority>0.5</priority>
</url>
<url>
<loc>https://sec.kaitan.id/search</loc>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://sec.kaitan.id/help</loc>
<changefreq>monthly</changefreq>
<priority>0.5</priority>
</url>
<url>
<loc>https://sec.kaitan.id/api-docs</loc>
<changefreq>monthly</changefreq>
<priority>0.5</priority>
</url>
<url>
<loc>https://sec.kaitan.id/legal/terms</loc>
<changefreq>yearly</changefreq>
<priority>0.3</priority>
</url>
<url>
<loc>https://sec.kaitan.id/legal/privacy</loc>
<changefreq>yearly</changefreq>
<priority>0.3</priority>
</url>
<url>
<loc>https://sec.kaitan.id/legal/cookies</loc>
<changefreq>yearly</changefreq>
<priority>0.3</priority>
</url>
<url>
<loc>https://sec.kaitan.id/legal/acceptable-use</loc>
<changefreq>yearly</changefreq>
<priority>0.3</priority>
</url>
<url>
<loc>https://sec.kaitan.id/legal/responsible-disclosure</loc>
<changefreq>yearly</changefreq>
<priority>0.3</priority>
</url>
<url>
<loc>https://sec.kaitan.id/llms.txt</loc>
<changefreq>monthly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-62379-critical-pre-auth-code-injection-in-openam-threatens-identity-inf-16220102</loc>
<lastmod>2026-09-15T18:00:35.237Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-90699-critical-command-injection-in-d-link-dwr-m920-router-16203162</loc>
<lastmod>2026-09-15T06:01:11.201Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-76461-critical-sql-injection-in-cisco-secure-email-gateway-allows-root--16194548</loc>
<lastmod>2026-09-15T00:00:41.144Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-90617-weaponized-command-injection-in-gh05tcrew-pentestagent-16184559</loc>
<lastmod>2026-09-14T18:01:11.528Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-90692-critical-weaponized-buffer-overflow-in-d-link-dir-878-dynamic-dns-16174757</loc>
<lastmod>2026-09-14T12:00:36.315Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-90605-critical-buffer-overflow-in-totolink-a3002mu-router-weaponized-ex-16166440</loc>
<lastmod>2026-09-14T06:00:39.249Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-90777-espnet-unsafe-deserialization-enables-remote-code-execution-16157926</loc>
<lastmod>2026-09-14T00:00:37.144Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-90493-weaponized-local-privilege-escalation-in-internet-download-manage-16149714</loc>
<lastmod>2026-09-13T18:00:36.741Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-90558-critical-stack-buffer-overflow-in-sngrep-sip-analyzer-cvss-98-16142263</loc>
<lastmod>2026-09-13T12:00:34.916Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-78006-critical-rce-in-the-events-calendar-wordpress-plugin-16126204</loc>
<lastmod>2026-09-13T00:01:24.966Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/kaitan-security-weekly-recap-sep-12-2026-205-criticals-9-kev-additions-16106918</loc>
<lastmod>2026-09-12T10:01:53.845Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-67277-mikrotik-routeros-missing-authentication-vulnerability-actively-e-16079002</loc>
<lastmod>2026-09-11T12:00:40.990Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-19490-critical-authentication-bypass-in-citrix-netscaler-adc-and-gatewa-16039797</loc>
<lastmod>2026-09-10T06:00:37.269Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-20079-critical-auth-bypass-in-cisco-fmc-grants-remote-root-access-16031183</loc>
<lastmod>2026-09-10T00:00:45.741Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-75650-critical-template-injection-in-adobe-commerce-and-magento-cvss-10-16024351</loc>
<lastmod>2026-09-09T18:00:40.789Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-86439-path-traversal-in-knowns-enables-full-filesystem-compromise-15996165</loc>
<lastmod>2026-09-08T18:00:44.439Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-13181-weaponized-telerik-ui-for-ajax-upload-metadata-flaw-scores-81-hig-15988145</loc>
<lastmod>2026-09-08T12:01:08.715Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-86151-critical-command-injection-in-tenda-cp3-firmware-15935191</loc>
<lastmod>2026-09-07T00:00:39.041Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-86148-critical-command-injection-in-tenda-cp3-firmware-15925983</loc>
<lastmod>2026-09-06T18:01:04.169Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-86152-critical-command-injection-in-tenda-cp3-firmware-cvss-100-15916875</loc>
<lastmod>2026-09-06T12:00:34.267Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-48019-crlf-injection-in-laravel-email-validation-weaponized-no-patch-ye-15899501</loc>
<lastmod>2026-09-06T00:00:38.605Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-22778-vllm-heap-address-leak-enabling-remote-code-execution-15890735</loc>
<lastmod>2026-09-05T18:01:04.335Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/vulnerability-recap-sep-5-2026-182-criticals-zero-patches-and-a-router-crisis-15879066</loc>
<lastmod>2026-09-05T10:00:53.661Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-56718-path-traversal-in-ajcloud-ajy-ipc-firmware-jdbhttpd-web-service-15839874</loc>
<lastmod>2026-09-04T06:01:05.819Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-0769-critical-unauthenticated-rce-in-langflow-via-eval-injection-15830963</loc>
<lastmod>2026-09-04T00:00:47.329Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-49869-critical-os-command-injection-in-kestra-oss-actively-exploited-15822062</loc>
<lastmod>2026-09-03T18:00:41.551Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-83549-sonicwall-sma1000-os-command-injection-actively-exploited-15804855</loc>
<lastmod>2026-09-03T06:00:46.398Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-82329-critical-jfrog-artifactory-auth-bypass-now-actively-exploited-15796600</loc>
<lastmod>2026-09-03T00:01:11.087Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-27475-critical-insecure-deserialization-in-spip-cms-enables-code-execut-15779381</loc>
<lastmod>2026-09-02T12:00:41.019Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-0768-critical-unauthenticated-rce-in-langflow-via-code-injection-15752947</loc>
<lastmod>2026-09-01T18:00:42.132Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-82668-command-injection-in-klaussilveira-gitlist-200-15736621</loc>
<lastmod>2026-09-01T06:00:41.271Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-81578-papercut-ngmf-missing-authentication-actively-exploited-15728681</loc>
<lastmod>2026-09-01T00:00:41.563Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-82078-papercut-ngmf-critical-unsafe-reflection-vulnerability-actively-e-15720464</loc>
<lastmod>2026-08-31T18:01:25.437Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-45833-critical-code-injection-in-chromadb-python-project-15712307</loc>
<lastmod>2026-08-31T12:01:16.073Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-55584-phpsysinfo-authentication-bypass-via-spoofed-access-control-15647530</loc>
<lastmod>2026-08-29T18:00:36.106Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/vulnerability-recap-aug-29-2026-184-criticals-zero-patches-ai-tools-under-fire-15635452</loc>
<lastmod>2026-08-29T10:01:46.570Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-23751-critical-unauthenticated-rce-in-tungsten-capture-via-net-remoting-15629214</loc>
<lastmod>2026-08-29T06:01:12.659Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-76060-zoneminder-os-command-injection-enables-full-remote-code-executio-15610799</loc>
<lastmod>2026-08-28T18:00:35.491Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-53362-linux-kernel-ipv6-fraggap-paged-allocation-vulnerability-15601294</loc>
<lastmod>2026-08-28T12:00:46.375Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2023-49105-owncloud-improper-authentication-cisa-kev-cvss-98-critical-15592086</loc>
<lastmod>2026-08-28T06:00:34.936Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2015-3246-red-hat-libuser-race-condition-actively-exploited-15548627</loc>
<lastmod>2026-08-27T00:01:23.628Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-79912-totolink-n600r-command-injection-via-getcurrenttime-function-15539460</loc>
<lastmod>2026-08-26T18:00:33.598Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2025-54897-weaponized-deserialization-rce-in-microsoft-sharepoint-15530283</loc>
<lastmod>2026-08-26T12:00:35.949Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-60004-gitea-code-injection-vulnerability-actively-exploited-in-the-wild-15512537</loc>
<lastmod>2026-08-26T00:00:34.006Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-75616-os-command-injection-in-tp-link-archer-c20-v6-web-management-inte-15462140</loc>
<lastmod>2026-08-24T18:01:14.767Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-24301-weaponized-command-injection-in-microsoft-copilot-risks-data-expo-15454112</loc>
<lastmod>2026-08-24T12:00:35.188Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-2329-critical-unauthenticated-rce-in-grandstream-gxp16xx-ip-phones-15444935</loc>
<lastmod>2026-08-24T06:00:43.403Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-78050-critical-weaponized-buffer-overflow-in-comfast-cf-n1-s-router-15413558</loc>
<lastmod>2026-08-23T12:00:34.929Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-77946-critical-stack-overflow-in-trendnet-tew-821dap-scores-perfect-10-15404687</loc>
<lastmod>2026-08-23T06:00:39.377Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-41451-command-injection-in-uac-unix-like-artifacts-collector-before-330-15385476</loc>
<lastmod>2026-08-22T18:00:37.186Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/weekly-vulnerability-recap-aug-22-2026-467-criticals-no-patches-in-sight-15371563</loc>
<lastmod>2026-08-22T10:00:53.628Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-69836-critical-microsoft-entra-id-rce-vulnerability-actively-exploited-15344626</loc>
<lastmod>2026-08-21T18:01:09.113Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-77148-critical-rce-vulnerability-in-comfast-cf-n1-s-firmware-15334857</loc>
<lastmod>2026-08-21T12:00:42.818Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2025-14601-os-command-injection-in-vsdesk-task-scheduler-15327752</loc>
<lastmod>2026-08-21T06:01:19.999Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-72529-trueconf-server-missing-authentication-critical-actively-exploite-15320657</loc>
<lastmod>2026-08-21T00:00:41.411Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-72530-critical-trueconf-server-code-injection-vulnerability-15317992</loc>
<lastmod>2026-08-20T18:01:16.005Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-64849-critical-ssrf-in-mlflow-actively-exploited-added-to-cisa-kev-15305855</loc>
<lastmod>2026-08-20T06:01:22.529Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-59310-critical-vmware-vcenter-directory-traversal-under-active-exploita-15286328</loc>
<lastmod>2026-08-19T18:00:38.307Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-55040-microsoft-sharepoint-server-security-feature-bypass-vulnerability-15276559</loc>
<lastmod>2026-08-19T12:01:11.404Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-33824-critical-windows-ike-double-free-rce-under-active-exploitation-15256149</loc>
<lastmod>2026-08-19T00:01:16.427Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-73522-stack-buffer-overflow-in-covesa-open1722-through-092-15249044</loc>
<lastmod>2026-08-18T18:01:25.383Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2025-62593-ray-project-ray-code-injection-actively-exploited-added-to-cisa-k-15242531</loc>
<lastmod>2026-08-18T12:00:40.069Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-73061-critical-access-modifier-bypass-in-scriban-template-engine-15205530</loc>
<lastmod>2026-08-17T12:00:39.445Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-19977-critical-authentication-bypass-in-efm-iptime-a3004t-router-15197241</loc>
<lastmod>2026-08-17T06:00:35.163Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-6837-weaponized-command-injection-in-zyxel-wax650s-export-cgi-15187176</loc>
<lastmod>2026-08-17T00:01:10.301Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-19924-critical-authentication-bypass-in-tenda-ac10-router-15177111</loc>
<lastmod>2026-08-16T18:01:14.823Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-73682-os-command-injection-in-semaphore-git_url-handling-cvss-88-15147846</loc>
<lastmod>2026-08-15T18:02:02.440Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/weekly-vulnerability-recap-aug-15-2026-260-criticals-no-patches-4-kev-additions-15136597</loc>
<lastmod>2026-08-15T10:00:56.990Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-19771-command-injection-in-baicells-eg3661m-firmware-15121008</loc>
<lastmod>2026-08-15T00:01:15.475Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-25938-critical-auth-bypass-rce-in-fuxa-scadahmi-software-15101295</loc>
<lastmod>2026-08-14T12:01:10.280Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-47717-fuxa-scadahmi-sensitive-data-exposure-via-unauthenticated-api-15084306</loc>
<lastmod>2026-08-14T00:01:09.310Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-73296-critical-auth-bypass-in-microsoft-ufo-automation-framework-cvss-9-15074647</loc>
<lastmod>2026-08-13T18:00:38.138Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-14282-critical-unrestricted-file-upload-in-godam-wordpress-plugin-15054462</loc>
<lastmod>2026-08-13T06:00:42.188Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-41452-critical-auth-bypass-in-krayin-crm-224-installer-middleware-15043805</loc>
<lastmod>2026-08-13T00:01:12.202Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-66804-windows-cross-device-service-elevation-of-privilege-deep-dive-15033148</loc>
<lastmod>2026-08-12T18:01:11.060Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-68820-windows-winsock-driver-use-after-free-actively-exploited-eop-15022686</loc>
<lastmod>2026-08-12T12:00:52.046Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-20349-cisco-asa-ftd-ssl-vpn-dos-vulnerability-actively-exploited-15012306</loc>
<lastmod>2026-08-12T06:00:34.841Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-72898-critical-sql-injection-in-metabase-allows-unauthenticated-admin-t-15001955</loc>
<lastmod>2026-08-12T00:00:37.895Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-71966-weaponized-command-injection-in-cyberpanel-243-remote-backup-feat-14991594</loc>
<lastmod>2026-08-11T18:00:34.582Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-19264-critical-path-traversal-in-postiz-social-media-scheduler-14970873</loc>
<lastmod>2026-08-11T06:01:09.989Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-19379-command-injection-in-efm-iptime-ax8004m-cgi-endpoint-14961836</loc>
<lastmod>2026-08-11T00:00:32.297Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2024-55591-fortinet-fortios-fortiproxy-authentication-bypass-under-active-ex-14953111</loc>
<lastmod>2026-08-10T18:00:36.611Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-4282-keycloak-authorization-code-forgery-enables-privilege-escalation-14943913</loc>
<lastmod>2026-08-10T12:01:12.611Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-19341-weaponized-buffer-overflow-in-utt-hiper-1200gw-router-14933517</loc>
<lastmod>2026-08-10T06:00:41.375Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-26119-weaponized-privilege-escalation-in-windows-admin-center-14921651</loc>
<lastmod>2026-08-10T00:01:07.277Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-49268-ldap-injection-in-apache-shiro-defaultldaprealm-high-severity-14887505</loc>
<lastmod>2026-08-09T06:01:13.398Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-19263-weaponized-injection-flaw-in-inquirelab-mcp-bridge-api-14863447</loc>
<lastmod>2026-08-08T18:00:34.980Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-18953-path-traversal-in-amazon-awslabs-aws-transform-mcp-server-14852457</loc>
<lastmod>2026-08-08T12:01:05.678Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/weekly-vulnerability-recap-aug-08-2026-210-criticals-zero-patches-and-a-maliciou-14848892</loc>
<lastmod>2026-08-08T10:00:51.841Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-61808-critical-unauthenticated-rce-risk-in-lightrag-api-server-14841169</loc>
<lastmod>2026-08-08T06:00:37.147Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-19196-high-severity-injection-flaw-in-sourcecodester-photo-share-websit-14829882</loc>
<lastmod>2026-08-08T00:01:12.967Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-4408-critical-weaponized-os-command-injection-in-samba-file-servers-14773788</loc>
<lastmod>2026-08-06T18:00:35.461Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-63077-jetbrains-teamcity-unauthenticated-rce-via-agent-polling-protocol-14763115</loc>
<lastmod>2026-08-06T12:00:42.035Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-18814-weaponized-command-injection-in-h3c-nx15-v100r017-network-device-14730786</loc>
<lastmod>2026-08-05T18:00:33.449Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-9198-critical-ibm-langflow-code-injection-actively-exploited-no-patch-a-14696630</loc>
<lastmod>2026-08-05T00:01:10.102Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-34486-apache-tomcat-encryptinterceptor-bypass-via-missing-encryption-14685343</loc>
<lastmod>2026-08-04T18:01:12.639Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-3611-honeywell-iq4x-bms-controller-exposes-full-hmi-without-authenticat-14674353</loc>
<lastmod>2026-08-04T12:01:07.270Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-42826-critical-azure-devops-information-disclosure-weaponized-no-patch--14663660</loc>
<lastmod>2026-08-04T06:00:35.207Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-18577-n-central-auth-bypass-actively-exploited-incomplete-patch-enables-14651672</loc>
<lastmod>2026-08-04T00:01:09.653Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-9848-sql-injection-in-wp-ticket-wordpress-plugin-versions-up-to-60-14639898</loc>
<lastmod>2026-08-03T18:01:11.026Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2025-10897-arbitrary-file-read-in-woocommerce-designer-pro-wordpress-theme-14592986</loc>
<lastmod>2026-08-02T18:01:16.381Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-14483-critical-arbitrary-file-upload-in-realtyna-wpl-real-estate-plugin-14581402</loc>
<lastmod>2026-08-02T12:01:16.359Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2025-15001-critical-wordpress-plugin-flaw-enables-unauthenticated-account-ta-14557948</loc>
<lastmod>2026-08-02T00:01:04.740Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2025-7384-critical-php-object-injection-in-wordpress-form-database-plugin-14545740</loc>
<lastmod>2026-08-01T18:00:33.256Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-17566-critical-os-command-injection-in-pgadmin-4-importexport-tool-14534186</loc>
<lastmod>2026-08-01T12:00:34.473Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/weekly-vulnerability-recap-aug-01-2026-136-criticals-zero-patches-14530853</loc>
<lastmod>2026-08-01T10:01:42.870Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-56671-path-traversal-in-comfyui-model-manager-exposes-sensitive-files-14522898</loc>
<lastmod>2026-08-01T06:00:35.702Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-66066-critical-active-storage-flaw-in-ruby-on-rails-with-weaponized-exp-14498997</loc>
<lastmod>2026-07-31T18:00:39.051Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-57827-critical-unauthenticated-rce-in-joomla-rsfiles-extension-14464694</loc>
<lastmod>2026-07-31T00:01:13.442Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-14266-7-zip-xz-decompression-heap-buffer-overflow-enables-remote-code-e-14452823</loc>
<lastmod>2026-07-30T18:01:04.072Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-20316-cisco-fmc-hard-coded-credential-flaw-actively-exploited-14419855</loc>
<lastmod>2026-07-30T00:00:40.666Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-33718-command-injection-in-openhands-ai-development-platform-14408271</loc>
<lastmod>2026-07-29T18:00:33.419Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-65893-insecure-debug-feature-in-cp-plus-ez-p21-ip-camera-firmware-14396390</loc>
<lastmod>2026-07-29T12:01:13.141Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-27577-critical-rce-in-n8n-workflow-automation-via-expression-injection-14385113</loc>
<lastmod>2026-07-29T06:00:36.297Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-16812-critical-os-command-injection-in-arista-velocloud-orchestrator-14361322</loc>
<lastmod>2026-07-28T18:00:40.793Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2025-68686-fortinet-fortios-sensitive-information-exposure-bypasses-symlink--14350392</loc>
<lastmod>2026-07-28T12:01:12.044Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-15981-critical-authentication-bypass-in-wordpress-saml-sso-plugin-14294111</loc>
<lastmod>2026-07-27T06:01:24.806Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-58480-critical-unauthenticated-file-upload-in-blocksy-companion-pro-for-14270076</loc>
<lastmod>2026-07-26T18:01:14.029Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-66012-critical-missing-authorization-in-siyuan-mcp-endpoint-cvss-100-14259176</loc>
<lastmod>2026-07-26T12:00:45.737Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-32194-critical-command-injection-in-microsoft-bing-images-14247592</loc>
<lastmod>2026-07-26T06:01:23.430Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-26216-critical-rce-in-crawl4ai-docker-api-via-unsafe-python-exec-14235424</loc>
<lastmod>2026-07-26T00:00:48.224Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-65711-os-command-injection-in-syspass-up-to-version-3211-14223386</loc>
<lastmod>2026-07-25T18:00:38.503Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/weekly-vulnerability-recap-jul-25-2026-348-criticals-no-patches-in-sight-14208176</loc>
<lastmod>2026-07-25T10:01:45.876Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-16870-stack-overflow-in-snowflake-libsnowflakeclient-enables-remote-cod-14200458</loc>
<lastmod>2026-07-25T06:01:14.641Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-60206-critical-oracle-weblogic-server-saml-takeover-vulnerability-14188420</loc>
<lastmod>2026-07-25T00:01:12.043Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-47668-critical-rce-in-dbgate-json-script-runner-cvss-100-14176679</loc>
<lastmod>2026-07-24T18:01:06.220Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-54121-ad-cs-elevation-of-privilege-weaponized-exploit-no-patch-yet-14165115</loc>
<lastmod>2026-07-24T12:00:36.403Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-16723-critical-rce-in-fastjson-12681283-weaponized-exploit-active-14154522</loc>
<lastmod>2026-07-24T06:01:14.860Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-16232-check-point-smartconsole-authentication-bypass-actively-exploited-14097110</loc>
<lastmod>2026-07-23T00:00:37.601Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-50522-critical-microsoft-sharepoint-rce-via-deserialization-no-patch-av-14085072</loc>
<lastmod>2026-07-22T18:00:35.765Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-60137-critical-sql-injection-in-wordpress-core-wp_query-14073191</loc>
<lastmod>2026-07-22T12:01:23.924Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2021-27137-dd-wrt-stack-based-buffer-overflow-under-active-exploitation-14062498</loc>
<lastmod>2026-07-22T06:00:40.464Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-63030-wordpress-rest-api-route-confusion-enables-unauthenticated-data-e-14052102</loc>
<lastmod>2026-07-22T00:01:14.785Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-0770-critical-unauthenticated-rce-in-langflow-via-exec_globals-paramete-14040518</loc>
<lastmod>2026-07-21T18:00:41.946Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2024-4068-memory-exhaustion-in-braces-npm-package-weaponized-dos-risk-14030122</loc>
<lastmod>2026-07-21T12:00:42.741Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-11374-critical-sso-authentication-bypass-in-manageengine-suite-14008747</loc>
<lastmod>2026-07-21T00:01:07.665Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-60121-critical-unauthenticated-os-command-injection-in-vitec-flamingo-4-13997016</loc>
<lastmod>2026-07-20T18:01:04.459Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-50402-windows-ntfs-elevation-of-privilege-vulnerability-weaponized-expl-13985572</loc>
<lastmod>2026-07-20T12:01:36.824Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2025-71392-critical-command-injection-in-surrealdb-export-command-13940844</loc>
<lastmod>2026-07-19T12:00:40.607Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-55173-os-command-injection-in-wwbn-avideo-v290-and-below-13859103</loc>
<lastmod>2026-07-17T18:00:34.337Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-50343-microsoft-install-service-elevation-of-privilege-vulnerability-13847115</loc>
<lastmod>2026-07-17T12:00:38.063Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-58644-critical-microsoft-sharepoint-rce-actively-exploited-in-the-wild-13836125</loc>
<lastmod>2026-07-17T06:01:07.248Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-39808-critical-os-command-injection-in-fortinet-fortisandbox-actively-e-13824279</loc>
<lastmod>2026-07-17T00:00:42.555Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-46817-critical-oracle-e-business-suite-payments-flaw-under-active-explo-13778258</loc>
<lastmod>2026-07-16T00:01:13.991Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-56164-microsoft-sharepoint-server-elevation-of-privilege-vulnerability-13766100</loc>
<lastmod>2026-07-15T18:01:04.537Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-15410-sonicwall-sma1000-code-injection-vulnerability-actively-exploited-13754823</loc>
<lastmod>2026-07-15T12:00:35.642Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-56155-ad-fs-elevation-of-privilege-actively-exploited-no-patch-availabl-13743536</loc>
<lastmod>2026-07-15T06:00:33.905Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-15409-critical-ssrf-in-sonicwall-sma1000-actively-exploited-no-patch-av-13731655</loc>
<lastmod>2026-07-15T00:00:37.651Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-57829-unauthenticated-stored-xss-in-joomla-helix-ultimate-extension-13707300</loc>
<lastmod>2026-07-14T12:01:15.151Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2024-52046-critical-apache-mina-deserialization-rce-weaponized-exploit-publi-13695726</loc>
<lastmod>2026-07-14T06:01:08.866Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2008-4128-cisco-ios-csrf-vulnerability-now-actively-exploited-13682954</loc>
<lastmod>2026-07-14T00:01:04.414Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-21055-weaponized-local-privilege-escalation-in-samsung-bixby-13658664</loc>
<lastmod>2026-07-13T12:01:02.778Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-34038-critical-os-command-injection-in-coolify-self-hosted-platform-13398842</loc>
<lastmod>2026-07-07T18:00:35.440Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-42980-windows-nt-os-kernel-elevation-of-privilege-vulnerability-13388075</loc>
<lastmod>2026-07-07T12:01:16.014Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-48282-critical-path-traversal-in-adobe-coldfusion-weaponized-exploit-av-13364293</loc>
<lastmod>2026-07-07T00:00:37.090Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-14802-command-injection-in-create-react-app-openbrowserjs-high-weaponiz-13352747</loc>
<lastmod>2026-07-06T18:00:31.314Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-25555-critical-authentication-bypass-in-openbullet2-api-middleware-13342212</loc>
<lastmod>2026-07-06T12:01:02.840Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-8713-critical-arbitrary-file-deletion-in-avada-fusion-builder-for-wordp-13330731</loc>
<lastmod>2026-07-06T06:00:35.388Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-14637-high-severity-improper-input-validation-in-kirilkirkov-ecommerce--13306622</loc>
<lastmod>2026-07-05T18:01:15.596Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-57517-critical-blind-sql-injection-in-control-web-panel-weaponized-expl-13294280</loc>
<lastmod>2026-07-05T12:00:38.359Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-54998-microsoft-exchange-online-elevation-of-privilege-weaponized-no-pa-13282512</loc>
<lastmod>2026-07-05T06:01:20.397Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-27771-gitea-composer-permission-bypass-exposes-private-repositories-13258116</loc>
<lastmod>2026-07-04T18:00:38.113Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/weekly-vulnerability-recap-jul-04-2026-coldfusion-stonefly-and-adobe-under-fire-13242043</loc>
<lastmod>2026-07-04T10:01:45.401Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-13768-critical-hard-coded-credentials-in-gardyn-iot-hub-enable-full-dev-13199132</loc>
<lastmod>2026-07-03T12:00:37.428Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-9563-eclipse-parsson-json-parser-dos-via-unbounded-character-processing-13187002</loc>
<lastmod>2026-07-03T06:00:41.080Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-33592-weaponized-memory-exhaustion-in-open62541-opc-ua-library-13175092</loc>
<lastmod>2026-07-03T00:01:07.992Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-58457-critical-os-command-injection-in-shenzhen-aitemi-m300-wi-fi-repea-13163284</loc>
<lastmod>2026-07-02T18:01:08.988Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-45659-microsoft-sharepoint-rce-actively-exploited-cisa-kev-listed-13129991</loc>
<lastmod>2026-07-02T00:00:36.463Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-56700-critical-remote-code-execution-in-grav-cms-via-unsafe-unserialize-13117996</loc>
<lastmod>2026-07-01T18:01:05.755Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-56413-critical-command-injection-in-storage-concentrator-ms_servicepl-c-13106178</loc>
<lastmod>2026-07-01T12:00:36.027Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-8023-path-traversal-in-zephyr-rtos-http-static-filesystem-server-13082950</loc>
<lastmod>2026-07-01T00:01:09.682Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-8037-critical-os-command-injection-rce-in-progress-adc-products-13070341</loc>
<lastmod>2026-06-30T18:01:10.678Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-48558-critical-simplehelp-authentication-bypass-actively-exploited-in-t-13046826</loc>
<lastmod>2026-06-30T06:00:42.931Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-22226-command-injection-in-tp-link-archer-be230-vpn-module-13022727</loc>
<lastmod>2026-06-29T18:00:33.583Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-13515-weaponized-buffer-overflow-in-tenda-jd12l-pptp-server-configurati-13010981</loc>
<lastmod>2026-06-29T12:00:38.327Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-12485-critical-stack-overflow-in-geovision-gv-io-box-4e-dvrsearch-servi-12987317</loc>
<lastmod>2026-06-29T00:01:21.574Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-58053-critical-container-escape-in-gitea-act_runner-docker-backend-12963606</loc>
<lastmod>2026-06-28T12:01:08.574Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-5366-critical-rce-in-prefect-3623-gitrepository-storage-class-12951838</loc>
<lastmod>2026-06-28T06:01:09.519Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-12415-critical-privilege-escalation-in-invoice-generator-wordpress-plug-12939783</loc>
<lastmod>2026-06-28T00:00:31.075Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-48778-notepad-os-command-injection-via-configxml-commandlineinterpreter-12927154</loc>
<lastmod>2026-06-27T18:00:34.766Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/vulnerability-recap-jun-27-2026-142-criticals-zero-patches-870-exploitable-cves-12910527</loc>
<lastmod>2026-06-27T10:00:50.413Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-40083-weaponized-sql-injection-in-cacti-affects-versions-1230-and-prior-12891060</loc>
<lastmod>2026-06-27T00:01:08.550Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-3227-tp-link-router-command-injection-grants-root-access-12867278</loc>
<lastmod>2026-06-26T12:01:07.050Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-12569-critical-rce-in-ptc-windchill-and-flexplm-actively-exploited-12855520</loc>
<lastmod>2026-06-26T06:01:12.744Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-20230-cisco-unified-cm-ssrf-vulnerability-actively-exploited-12842729</loc>
<lastmod>2026-06-26T00:00:34.284Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-54066-siyuan-path-traversal-bypass-weaponized-exploit-no-patch-availabl-12830015</loc>
<lastmod>2026-06-25T18:00:38.037Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-12416-critical-account-takeover-via-password-reset-in-wordpress-invoice-12817980</loc>
<lastmod>2026-06-25T12:00:38.990Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-54157-critical-ssrf-in-lobehub-webapiproxy-endpoint-12781680</loc>
<lastmod>2026-06-24T18:00:46.577Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2025-67038-critical-os-command-injection-in-lantronix-eds5000-exploited-in-t-12745400</loc>
<lastmod>2026-06-24T00:00:40.369Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-48746-critical-http-smuggling-flaw-in-vllm-inference-engine-12733003</loc>
<lastmod>2026-06-23T18:01:19.596Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-12866-critical-code-execution-in-expr-eval-via-tojsfunction-api-12720848</loc>
<lastmod>2026-06-23T12:00:40.457Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-49772-critical-sql-injection-in-the-events-calendar-liquid-web-stellarw-12708565</loc>
<lastmod>2026-06-23T06:01:15.313Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-48909-critical-unauthenticated-rce-via-deserialization-in-sp-lms-for-jo-12683354</loc>
<lastmod>2026-06-22T18:00:40.507Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-4020-gravity-smtp-plugin-exposes-full-system-report-to-unauthenticated--12670909</loc>
<lastmod>2026-06-22T12:01:16.210Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-56265-critical-authentication-bypass-in-crawl4ai-docker-api-via-hardcod-12658741</loc>
<lastmod>2026-06-22T06:00:39.713Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-48908-critical-unauthenticated-file-upload-rce-in-sp-page-builder-for-j-12646278</loc>
<lastmod>2026-06-22T00:00:37.371Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-49757-critical-auth-bypass-in-ashauthentication-enables-account-takeove-12633803</loc>
<lastmod>2026-06-21T18:01:13.287Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2019-25763-critical-authentication-bypass-in-ultimate-addons-for-beaver-buil-12621041</loc>
<lastmod>2026-06-21T12:00:38.694Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2024-58351-critical-code-injection-in-flowise-chainflow-via-overrideconfig-12608224</loc>
<lastmod>2026-06-21T06:00:38.447Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/weekly-vulnerability-recap-jun-20-2026-167-criticals-wordpress-rce-surge-and-zer-12566174</loc>
<lastmod>2026-06-20T10:00:51.795Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-42055-high-severity-heap-buffer-overflow-in-nginx-plus-and-open-source-12545645</loc>
<lastmod>2026-06-20T00:01:16.641Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-10523-critical-authentication-bypass-in-ivanti-sentry-cvss-99-12532948</loc>
<lastmod>2026-06-19T18:00:36.912Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-42530-use-after-free-in-nginx-http3-quic-module-rated-high-12520156</loc>
<lastmod>2026-06-19T12:01:13.245Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-53676-thingsboard-prototype-pollution-enabling-sandboxed-code-execution-12494653</loc>
<lastmod>2026-06-19T00:01:13.285Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-20253-critical-unauthenticated-file-manipulation-in-splunk-enterprise-a-12481916</loc>
<lastmod>2026-06-18T18:00:46.678Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-7654-wordpress-admin-columns-plugin-rce-via-php-object-injection-12443335</loc>
<lastmod>2026-06-18T00:00:40.470Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-53776-critical-jwt-bypass-in-perry-allows-remote-authentication-evasion-12418396</loc>
<lastmod>2026-06-17T12:00:40.900Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-48777-critical-path-traversal-in-filebrowser-quantum-actively-weaponize-12406223</loc>
<lastmod>2026-06-17T06:00:36.342Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-48907-critical-unauthenticated-rce-in-joomla-content-editor-jce-12392932</loc>
<lastmod>2026-06-17T00:01:17.087Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-20262-cisco-catalyst-sd-wan-manager-arbitrary-file-write-vulnerability-12379566</loc>
<lastmod>2026-06-16T18:00:37.196Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-54420-litespeed-cpanel-plugin-symlink-vulnerability-actively-exploited-12366794</loc>
<lastmod>2026-06-16T12:00:43.058Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-12197-weaponized-injection-flaw-in-ruijie-eg105g-p-network-gateway-12328193</loc>
<lastmod>2026-06-15T18:00:39.226Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-48611-critical-oauth-authentication-bypass-enables-account-hijacking-12262894</loc>
<lastmod>2026-06-14T12:00:41.897Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-22356-php-local-file-inclusion-in-automattic-jetpack-crm-12250419</loc>
<lastmod>2026-06-14T06:01:06.623Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-42647-critical-blind-sql-injection-in-beardev-joomsport-weaponized-expl-12237944</loc>
<lastmod>2026-06-14T00:00:41.655Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-53836-openclaw-powershell-allowlist-bypass-allows-remote-code-execution-12224281</loc>
<lastmod>2026-06-13T18:00:43.962Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-8809-critical-privilege-escalation-in-advanced-custom-fields-extended-f-12210915</loc>
<lastmod>2026-06-13T12:01:11.383Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/weekly-vulnerability-recap-jun-13-2026-ivanti-vm2-and-adobe-under-fire-12206756</loc>
<lastmod>2026-06-13T10:00:55.583Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-47208-critical-vm2-sandbox-breakout-cvss-100-with-weaponized-exploit-12198479</loc>
<lastmod>2026-06-13T06:00:44.665Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-35273-critical-oracle-peoplesoft-unauthenticated-rce-under-active-explo-12186039</loc>
<lastmod>2026-06-13T00:01:20.782Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-49777-critical-unauthenticated-rce-in-product-slider-pro-for-woocommerc-12172608</loc>
<lastmod>2026-06-12T18:01:09.857Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-10520-critical-rce-in-ivanti-sentry-perfect-cvss-score-actively-exploit-12135195</loc>
<lastmod>2026-06-12T00:01:25.620Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-46522-imagemagick-uncontrolled-resource-consumption-weaponized-dos-flaw-12122141</loc>
<lastmod>2026-06-11T18:00:40.304Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-25089-critical-os-command-injection-in-fortinet-fortisandbox-12084346</loc>
<lastmod>2026-06-11T00:01:17.496Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-7473-arista-eos-tunnel-decap-flaw-actively-exploited-added-to-cisa-kev-12071040</loc>
<lastmod>2026-06-10T18:01:20.068Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-20245-cisco-catalyst-sd-wan-manager-cli-privilege-escalation-under-acti-12034301</loc>
<lastmod>2026-06-10T00:00:39.962Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-11556-weaponized-command-injection-in-tenda-f451-router-12021981</loc>
<lastmod>2026-06-09T18:01:14.342Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-11504-weaponized-buffer-overflow-in-tenda-cx12l-router-12009678</loc>
<lastmod>2026-06-09T12:00:45.787Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-11499-critical-stack-overflow-in-tenda-hg7hg9hg10-routers-11997213</loc>
<lastmod>2026-06-09T06:01:22.373Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-50751-check-point-vpn-zero-day-actively-exploited-in-the-wild-11984748</loc>
<lastmod>2026-06-09T00:01:14.259Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-42271-litellm-command-injection-via-mcp-server-test-endpoints-11970933</loc>
<lastmod>2026-06-08T18:00:40.886Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2023-54352-critical-unauthenticated-rce-in-wordpress-seotheme-plugin-11958066</loc>
<lastmod>2026-06-08T12:00:41.724Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-11457-weaponized-injection-flaw-in-erzhongxmu-jeewms-11945995</loc>
<lastmod>2026-06-08T06:00:41.061Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-11451-weaponized-injection-flaw-in-glinet-gl-mt3000-ftp-handler-11933478</loc>
<lastmod>2026-06-08T00:00:43.112Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-11450-glinet-gl-mt3000-dlopen-path-injection-enables-unauthenticated-rc-11919760</loc>
<lastmod>2026-06-07T18:00:39.836Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-10580-critical-auth-bypass-in-hippoo-woocommerce-plugin-allows-admin-ta-11894342</loc>
<lastmod>2026-06-07T06:01:11.684Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-9290-wp-user-manager-local-file-inclusion-weaponized-unpatched-11881615</loc>
<lastmod>2026-06-07T00:01:15.267Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-3300-critical-rce-via-php-code-injection-in-everest-forms-pro-for-wordp-11854909</loc>
<lastmod>2026-06-06T12:00:45.349Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/weekly-vulnerability-recap-jun-06-2026-91-criticals-zero-patches-11850760</loc>
<lastmod>2026-06-06T10:00:57.725Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-28318-solarwinds-serv-u-unauthenticated-dos-via-uncontrolled-resource-c-11830296</loc>
<lastmod>2026-06-06T00:00:36.022Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-26179-windows-kernel-elevation-of-privilege-via-double-free-11804169</loc>
<lastmod>2026-06-05T12:01:17.559Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-3180-unauthenticated-blind-sql-injection-in-contest-gallery-wordpress-p-11792001</loc>
<lastmod>2026-06-05T06:00:42.917Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-10777-improper-authentication-in-ealpha072-student-management-system-11765607</loc>
<lastmod>2026-06-04T18:00:41.346Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-41283-critical-rce-in-openstack-mistral-demands-immediate-action-11753314</loc>
<lastmod>2026-06-04T12:00:40.294Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-45247-mirasvit-full-page-cache-warmer-deserialization-actively-exploite-11740974</loc>
<lastmod>2026-06-04T06:00:39.325Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2025-9209-critical-auth-bypass-in-restropress-wordpress-plugin-via-jwt-token-11702992</loc>
<lastmod>2026-06-03T12:00:43.600Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2025-48595-android-framework-integer-overflow-enables-local-privilege-escala-11691111</loc>
<lastmod>2026-06-03T06:01:14.910Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2022-0492-linux-kernel-improper-authentication-vulnerability-now-in-cisa-kev-11678676</loc>
<lastmod>2026-06-03T00:01:15.838Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2023-39325-http2-rapid-reset-dos-in-nethttp-weaponized-exploit-available-11654024</loc>
<lastmod>2026-06-02T12:01:15.165Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2024-21182-oracle-weblogic-server-under-active-exploitation-act-now-11629382</loc>
<lastmod>2026-06-02T00:00:39.352Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-10219-weaponized-command-injection-in-nextlevelbuilder-goclaw-11616016</loc>
<lastmod>2026-06-01T18:01:15.565Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-41089-critical-windows-netlogon-rce-via-stack-buffer-overflow-11603244</loc>
<lastmod>2026-06-01T12:00:37.475Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-10167-authentication-bypass-in-brinarybrains-school-student-management--11591277</loc>
<lastmod>2026-06-01T06:00:41.646Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2025-10162-unauthenticated-path-traversal-in-orderconvo-wordpress-plugin-11578484</loc>
<lastmod>2026-06-01T00:01:08.590Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-7465-rce-in-spectra-gutenberg-blocks-wordpress-plugin-weaponized-exploi-11565292</loc>
<lastmod>2026-05-31T18:00:36.270Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2025-5947-critical-auth-bypass-enables-admin-takeover-in-wordpress-service-f-11527804</loc>
<lastmod>2026-05-31T00:00:36.414Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-46372-server-side-request-forgery-high-in-sillytavern-weaponized-exploi-11514197</loc>
<lastmod>2026-05-30T18:00:43.747Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/weekly-vulnerability-recap-may-30-2026-dokploy-iot-and-oracle-under-fire-11506119</loc>
<lastmod>2026-05-30T14:10:58.283Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/cve-2026-0257-pan-os-globalprotect-authentication-bypass-active-exploitation-con-11506118</loc>
<lastmod>2026-05-30T14:08:56.985Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/719-exploits-114-criticals-cisco-and-more-rock-cybersecurity-week-10668935</loc>
<lastmod>2026-05-16T10:00:42.962Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/123-critical-cves-and-611-exploitable-flaws-rock-cybersecurity-this-week-10263368</loc>
<lastmod>2026-05-09T10:00:50.134Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/66-criticals-561-exploitable-cyber-threats-surge-in-the-last-week-of-april-9855760</loc>
<lastmod>2026-05-02T10:00:41.969Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/april-2026-a-blog-a-newsletter-and-the-world-9804103</loc>
<lastmod>2026-05-01T09:00:00.000Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/106-criticals-628-exploitable-your-apr-18-25-cybersecurity-wake-up-call-9440607</loc>
<lastmod>2026-04-25T10:00:44.879Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/95-critical-cves-and-459-exploitable-flaws-dominate-a-turbulent-week-in-security-9033155</loc>
<lastmod>2026-04-18T10:00:39.238Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://sec.kaitan.id/blog/89-criticals-513-exploitable-this-weeks-cve-storm-mar-31apr-7-8411358</loc>
<lastmod>2026-04-07T22:20:49.747Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
</urlset>
