<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  <url>
    <loc>https://0daynews.com/articles/2026-09-27-budibase-3-45-0-six-cve-patch/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-27T12:00:00.000Z</news:publication_date>
      <news:title>Budibase 3.45.0 Fixes Six Security Flaws</news:title>
      <news:keywords>budibase, cve, authentication-bypass, sql-injection, arbitrary-file-write, ssrf, low-code</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-27-budibase-3-45-0-six-cve-patch/cover.jpg</image:loc>
      <image:title>Budibase 3.45.0 Fixes Six Security Flaws</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-27-citrix-netscaler-two-unpatched-rce-zero-days/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-27T10:30:00.000Z</news:publication_date>
      <news:title>Citrix NetScaler: Two Unpatched RCEs Actively Exploited</news:title>
      <news:keywords>citrix, netscaler, rce, zero-day, adc, gateway, exploitation</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-27-citrix-netscaler-two-unpatched-rce-zero-days/cover.jpg</image:loc>
      <image:title>Citrix NetScaler: Two Unpatched RCEs Actively Exploited</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-27-woocommerce-request-quote-cve-2026-18143-file-upload/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-27T08:00:00.000Z</news:publication_date>
      <news:title>Critical File Upload Bug in WooCommerce Quote Plugin</news:title>
      <news:keywords>woocommerce, cve-2026-18143, arbitrary-file-upload, wordpress, request-a-quote</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-27-woocommerce-request-quote-cve-2026-18143-file-upload/cover.jpg</image:loc>
      <image:title>Critical File Upload Bug in WooCommerce Quote Plugin</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-27-sharepoint-code-injection-cve-2026-65660-kev/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-27T06:00:00.000Z</news:publication_date>
      <news:title>SharePoint Code Injection CVE-2026-65660 Added to KEV</news:title>
      <news:keywords>sharepoint, cisa-kev, cve-2026-65660, code-injection, microsoft</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-27-sharepoint-code-injection-cve-2026-65660-kev/cover.jpg</image:loc>
      <image:title>SharePoint Code Injection CVE-2026-65660 Added to KEV</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-27-shinyhunters-waf-bypass-oracle-peoplesoft-cve-2026-35273/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-27T06:00:00.000Z</news:publication_date>
      <news:title>ShinyHunters WAF Bypass Keeps PeopleSoft Attacks Alive</news:title>
      <news:keywords>CVE-2026-35273, Oracle PeopleSoft, WAF bypass, ShinyHunters, web shells, KEV, URL encoding</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-27-shinyhunters-waf-bypass-oracle-peoplesoft-cve-2026-35273/cover.jpg</image:loc>
      <image:title>ShinyHunters WAF Bypass Keeps PeopleSoft Attacks Alive</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-26-elementor-csrf-admin-account-creation/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T14:00:00.000Z</news:publication_date>
      <news:title>Elementor CSRF Flaw Lets Attackers Create Admin Accounts</news:title>
      <news:keywords>wordpress, elementor, csrf, privilege-escalation, plugin-security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-26-elementor-csrf-admin-account-creation/cover.jpg</image:loc>
      <image:title>Elementor CSRF Flaw Lets Attackers Create Admin Accounts</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-26-mikrotik-cve-2026-67279-cisa-kev-chain/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T14:00:00.000Z</news:publication_date>
      <news:title>CISA Adds MikroTik RouterOS Chain Flaw to KEV Catalog</news:title>
      <news:keywords>mikrotik, routeros, cve-2026-67279, cve-2026-86060, cisa kev, vulnerability chain, network security</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-26-mikrotik-cve-2026-67279-cisa-kev-chain/cover.jpg</image:loc>
      <image:title>CISA Adds MikroTik RouterOS Chain Flaw to KEV Catalog</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-26-kiteworks-zero-day-warning-server-shutdown/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T12:00:00.000Z</news:publication_date>
      <news:title>Kiteworks Flags Potential Zero-Day, Urges Server Shutdown</news:title>
      <news:keywords>kiteworks, zero-day, managed file transfer, enterprise security, secure file sharing, mft</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-26-kiteworks-zero-day-warning-server-shutdown/cover.jpg</image:loc>
      <image:title>Kiteworks Flags Potential Zero-Day, Urges Server Shutdown</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-26-clop-moves-leak-site-grav-cms-attack-confirmed/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T08:00:00.000Z</news:publication_date>
      <news:title>Clop Moves Leak Site After Grav CMS Attack Confirmed</news:title>
      <news:keywords>Clop, ShinyHunters, Grav CMS, ransomware, path traversal, data leak site, threat actors</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-26-clop-moves-leak-site-grav-cms-attack-confirmed/cover.jpg</image:loc>
      <image:title>Clop Moves Leak Site After Grav CMS Attack Confirmed</image:title>
    </image:image>
  </url>
  <url>
    <loc>https://0daynews.com/articles/2026-09-26-soldier-70-months-att-verizon-telecom-extortion/</loc>
    <news:news>
      <news:publication>
        <news:name>0dayNews</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-26T06:00:00.000Z</news:publication_date>
      <news:title>U.S. Soldier Gets 70 Months for Telecom Extortion</news:title>
      <news:keywords>AT&amp;T, Verizon, telecom, extortion, sentencing, data theft, US Army</news:keywords>
    </news:news>
    <image:image>
      <image:loc>https://0daynews.com/articles/2026-09-26-soldier-70-months-att-verizon-telecom-extortion/cover.jpg</image:loc>
      <image:title>U.S. Soldier Gets 70 Months for Telecom Extortion</image:title>
    </image:image>
  </url>
</urlset>