<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://0daynews.com/articles/2026-09-22-wordpress-comment2shell-xss-rce-core/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T10:00:00.000Z</news:publication_date>
      <news:title>WordPress Core XSS Flaw Enables RCE via Admin Sessions</news:title>
      <news:keywords>WordPress, XSS, RCE, stored cross-site scripting, comment injection, admin session, web security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-22-wordpress-comment2shell-xss-rce-core/cover.jpg</image:loc>
      <image:title>WordPress Core XSS Flaw Enables RCE via Admin Sessions</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-22-zyxel-veeam-kev-active-exploitation/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T09:00:00.000Z</news:publication_date>
      <news:title>Zyxel, Veeam Flaws Confirmed Under Active Exploitation</news:title>
      <news:keywords>zyxel, veeam, cve-2026-7273, cve-2026-32996, cisa-kev, active exploitation, privilege escalation</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-22-zyxel-veeam-kev-active-exploitation/cover.jpg</image:loc>
      <image:title>Zyxel, Veeam Flaws Confirmed Under Active Exploitation</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-22-shinyhunters-extorts-clop-victim-data-at-risk/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T08:00:00.000Z</news:publication_date>
      <news:title>ShinyHunters Extorts Cl0p, Victim Data at Risk</news:title>
      <news:keywords>ShinyHunters, Cl0p, ransomware, extortion, victim data, cybercrime</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-22-shinyhunters-extorts-clop-victim-data-at-risk/cover.jpg</image:loc>
      <image:title>ShinyHunters Extorts Cl0p, Victim Data at Risk</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-22-bigcommerce-ribon-app-supply-chain-breach/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T06:00:00.000Z</news:publication_date>
      <news:title>BigCommerce Merchants Breached via Ribon App Credentials</news:title>
      <news:keywords>bigcommerce, supply-chain, data-breach, ribon, script-injection, third-party, e-commerce</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-22-bigcommerce-ribon-app-supply-chain-breach/cover.jpg</image:loc>
      <image:title>BigCommerce Merchants Breached via Ribon App Credentials</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-21-crowdsec-source-code-stolen-tanstack-supply-chain/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T10:00:00.000Z</news:publication_date>
      <news:title>CrowdSec Source Code Stolen in TanStack Attack</news:title>
      <news:keywords>crowdsec, supply-chain, source-code, tanstack, breach</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-21-crowdsec-source-code-stolen-tanstack-supply-chain/cover.jpg</image:loc>
      <image:title>CrowdSec Source Code Stolen in TanStack Attack</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-21-keycloak-four-cves-iam-patch/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T10:00:00.000Z</news:publication_date>
      <news:title>Red Hat Patches Four Keycloak IAM Flaws</news:title>
      <news:keywords>keycloak, red-hat, iam, authentication, authorization, cve, identity-management</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-21-keycloak-four-cves-iam-patch/cover.jpg</image:loc>
      <image:title>Red Hat Patches Four Keycloak IAM Flaws</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-21-jade-sleet-india-it-provider-flatroof-roofdeck/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T09:00:00.000Z</news:publication_date>
      <news:title>Jade Sleet Hits Indian IT Firm with Custom Backdoors</news:title>
      <news:keywords>jade-sleet, north-korea, apt, supply-chain, flatroof, roofdeck, india</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-21-jade-sleet-india-it-provider-flatroof-roofdeck/cover.jpg</image:loc>
      <image:title>Jade Sleet Hits Indian IT Firm with Custom Backdoors</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-21-nvm-cve-2026-94185-path-traversal-alias/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T09:00:00.000Z</news:publication_date>
      <news:title>CVE-2026-94185: nvm Alias Path Traversal, Update Now</news:title>
      <news:keywords>nvm, path-traversal, CVE-2026-94185, nodejs, supply-chain, developer-tools, ci-cd</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-21-nvm-cve-2026-94185-path-traversal-alias/cover.jpg</image:loc>
      <image:title>CVE-2026-94185: nvm Alias Path Traversal, Update Now</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-21-redcap-cve-2026-90817-unauth-rce/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-21T06:00:00.000Z</news:publication_date>
      <news:title>REDCap Patches CVSS 9.8 Unauth RCE via Survey Route</news:title>
      <news:keywords>REDCap, CVE-2026-90817, remote code execution, unauthenticated RCE, clinical research, medical research security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-21-redcap-cve-2026-90817-unauth-rce/cover.jpg</image:loc>
      <image:title>REDCap Patches CVSS 9.8 Unauth RCE via Survey Route</image:title>
    </image:image>
  </url>
</urlset>