<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://0daynews.com/articles/2026-09-17-wso2-cve-2026-5430-cvss10-jwt-bypass-exploited/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T15:00:00.000Z</news:publication_date>
      <news:title>WSO2 CVSS 10 JWT Bypass Exploited in the Wild</news:title>
      <news:keywords>WSO2, CVE-2026-5430, JWT, authentication bypass, CVSS 10, API, enterprise, identity</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-17-wso2-cve-2026-5430-cvss10-jwt-bypass-exploited/cover.jpg</image:loc>
      <image:title>WSO2 CVSS 10 JWT Bypass Exploited in the Wild</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-17-google-pixel-september-2026-modem-zero-day-cve-2026-58704/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T14:00:00.000Z</news:publication_date>
      <news:title>Google Patches Pixel Modem Zero-Day Under Attack</news:title>
      <news:keywords>Google Pixel, CVE-2026-58704, KEV, Android, modem zero-day, CISA, privilege escalation</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-17-google-pixel-september-2026-modem-zero-day-cve-2026-58704/cover.jpg</image:loc>
      <image:title>Google Patches Pixel Modem Zero-Day Under Attack</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-17-cisco-ise-cve-2026-76460-cvss10-auth-bypass/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T12:00:00.000Z</news:publication_date>
      <news:title>Cisco ISE Zero-Day CVSS 10.0 Under Active Exploitation</news:title>
      <news:keywords>cisco, identity-services-engine, CVE-2026-76460, authentication-bypass, kev, zero-day</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-17-cisco-ise-cve-2026-76460-cvss10-auth-bypass/cover.jpg</image:loc>
      <image:title>Cisco ISE Zero-Day CVSS 10.0 Under Active Exploitation</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-17-misp-cve-2026-90895-cli-auth-bypass/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T07:00:00.000Z</news:publication_date>
      <news:title>CVE-2026-90895: MISP CLI Exposes Auth Creds, Bypasses ACLs</news:title>
      <news:keywords>MISP, CVE-2026-90895, authorization bypass, threat intelligence, credential exposure, CLI security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-17-misp-cve-2026-90895-cli-auth-bypass/cover.jpg</image:loc>
      <image:title>CVE-2026-90895: MISP CLI Exposes Auth Creds, Bypasses ACLs</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-17-mattermost-cve-2026-14344-board-auth-bypass/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-17T04:00:00.000Z</news:publication_date>
      <news:title>Mattermost CVE-2026-14344: Board Permission Check Skipped</news:title>
      <news:keywords>mattermost, authorization-bypass, CVE-2026-14344, rbac, boards, collaboration-security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-17-mattermost-cve-2026-14344-board-auth-bypass/cover.jpg</image:loc>
      <image:title>Mattermost CVE-2026-14344: Board Permission Check Skipped</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-16-d-link-dwr-m921-m920-command-injection-three-cves/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T16:00:00.000Z</news:publication_date>
      <news:title>D-Link DWR Routers Hit by Three Critical Command Injections</news:title>
      <news:keywords>D-Link, command injection, DWR-M921, DWR-M920, router vulnerabilities, firmware security, CVE-2026-90702</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-16-d-link-dwr-m921-m920-command-injection-three-cves/cover.jpg</image:loc>
      <image:title>D-Link DWR Routers Hit by Three Critical Command Injections</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-16-gitlab-cve-2026-85706-rapid7-exploitation-tracking/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T14:00:00.000Z</news:publication_date>
      <news:title>Rapid7 Tracks Active Exploits Against GitLab Path Traversal</news:title>
      <news:keywords>CVE-2026-85706, GitLab, path traversal, CISA KEV, Rapid7, exploitation</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-16-gitlab-cve-2026-85706-rapid7-exploitation-tracking/cover.jpg</image:loc>
      <image:title>Rapid7 Tracks Active Exploits Against GitLab Path Traversal</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-16-apache-syncope-seven-critical-cves-patch/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T10:00:00.000Z</news:publication_date>
      <news:title>Apache Syncope Patches 7 Critical Flaws</news:title>
      <news:keywords>apache, syncope, identity-management, sql-injection, jwt, authentication-bypass, patch</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-16-apache-syncope-seven-critical-cves-patch/cover.jpg</image:loc>
      <image:title>Apache Syncope Patches 7 Critical Flaws</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-16-lightllm-cve-2026-90919-rce-pickle/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T06:00:00.000Z</news:publication_date>
      <news:title>LightLLM Config Server Has Unauthenticated RCE</news:title>
      <news:keywords>CVE-2026-90919, LightLLM, pickle deserialization, remote code execution, AI infrastructure, unauthenticated, ModelTC</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-16-lightllm-cve-2026-90919-rce-pickle/cover.jpg</image:loc>
      <image:title>LightLLM Config Server Has Unauthenticated RCE</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-16-jfrog-artifactory-three-flaws-backdoor/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-16T04:00:00.000Z</news:publication_date>
      <news:title>Three Artifactory Flaws Exploited to Plant Backdoors</news:title>
      <news:keywords>JFrog, Artifactory, supply chain, backdoor, authentication bypass, privilege escalation, CVE-2026-82329</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-16-jfrog-artifactory-three-flaws-backdoor/cover.jpg</image:loc>
      <image:title>Three Artifactory Flaws Exploited to Plant Backdoors</image:title>
    </image:image>
  </url>
</urlset>