<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://cyberdeltaforce.ai/news/269f24178411f26c1569</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T10:16:43.900Z</news:publication_date>
      <news:title>CVE-2026-86124: AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplie</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d14134bce48d8f712bc1</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T10:16:43.463Z</news:publication_date>
      <news:title>CVE-2026-86121: Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by def</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/0c69396b931ad0a474fa</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T04:18:05.063Z</news:publication_date>
      <news:title>CVE-2026-83711: Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/99410d3277fa10ea25ea</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T04:18:04.943Z</news:publication_date>
      <news:title>CVE-2026-80098: Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/62b223c3276e5c178ab4</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T04:18:04.830Z</news:publication_date>
      <news:title>CVE-2026-70352: Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/9a85ebc9cdd2bfc2facb</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T04:18:04.033Z</news:publication_date>
      <news:title>CVE-2026-62916: Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b4a2bf421d6ca128f635</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T20:46:01.823Z</news:publication_date>
      <news:title>CVE-2026-64384: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/7c4baef8ec3ed59b033a</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T20:17:21.257Z</news:publication_date>
      <news:title>CVE-2025-12543: A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to pro</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/69031310b6ff3893bfe5</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T04:18:06.197Z</news:publication_date>
      <news:title>CVE-2026-85050: Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the san</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/87b316a5b7192a9964b9</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T04:18:04.610Z</news:publication_date>
      <news:title>CVE-2026-85047: Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/72799ad71ff7bb42d5f8</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T04:18:02.517Z</news:publication_date>
      <news:title>CVE-2026-85042: Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a craft</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/4f88073eb47cd9419193</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T21:16:51.400Z</news:publication_date>
      <news:title>CVE-2026-86060: RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/c6b36fb39569fde91388</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T21:16:49.387Z</news:publication_date>
      <news:title>CVE-2026-67276: RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/3b6a1455ce81c1423299</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T14:17:22.977Z</news:publication_date>
      <news:title>CVE-2026-16242: A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b2f973478aa0c7330deb</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T14:17:22.187Z</news:publication_date>
      <news:title>CVE-2026-10090: A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernete</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/c4681389c3fbdb232fb4</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T09:16:48.880Z</news:publication_date>
      <news:title>CVE-2024-11080: The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/fe70be5b33445e92e6eb</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T03:17:24.303Z</news:publication_date>
      <news:title>CVE-2026-85434: MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROK</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/c2b07ee14b2df8dbb52d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T03:17:24.050Z</news:publication_date>
      <news:title>CVE-2026-85424: MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/2572b2b1770708702c61</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T20:06:02.093Z</news:publication_date>
      <news:title>CVE-2026-22752: Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Serve</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/e9fc8e113da253a699b8</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T20:02:09.230Z</news:publication_date>
      <news:title>CVE-2025-15379: A command injection vulnerability exists in MLflow&apos;s model serving container initialization code, specifically in the `_install_model_dependencies_to_</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/100625050bfeec8edf6a</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T10:17:13.900Z</news:publication_date>
      <news:title>CVE-2026-85184: @fastify/middie versions &gt;= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d5545408b64065e52101</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T10:17:13.340Z</news:publication_date>
      <news:title>CVE-2026-82923: The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauth</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/843ba8df966d9e43e4fb</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T03:17:41.507Z</news:publication_date>
      <news:title>CVE-2026-53649: Joro is a web exploitation framework. Prior to version 1.1.1, Joro&apos;s default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authent</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d4e8b894c262c3a6e552</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T13:18:14.150Z</news:publication_date>
      <news:title>CVE-2026-86190: WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, r</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d10f9d5b6b23069207f7</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T13:18:14.000Z</news:publication_date>
      <news:title>CVE-2026-86189: WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locati</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/0c77a7036a7818220f16</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T02:17:18.930Z</news:publication_date>
      <news:title>CVE-2026-85154: WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that gra</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/ff1c7eda368e65a86578</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T22:17:17.723Z</news:publication_date>
      <news:title>CVE-2026-61884: The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/6ef70e4d024507680f61</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T19:08:35.457Z</news:publication_date>
      <news:title>CVE-2026-64393: In the Linux kernel, the following vulnerability has been resolved: ksmbd: run set info with opener credentials SMB2 SET_INFO handlers call path-bas</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/cd778c651279d4116f9e</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T14:13:32.820Z</news:publication_date>
      <news:title>CVE-2024-28056: Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authenticat</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/41b0d0701e026774a9dc</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T15:17:31.100Z</news:publication_date>
      <news:title>CVE-2026-73269: A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, c</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/93fb96cc6ba5acb8c6ee</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T15:17:30.963Z</news:publication_date>
      <news:title>CVE-2026-73268: A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurato</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d67f2b17e03c2e5bd3cc</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T15:17:29.240Z</news:publication_date>
      <news:title>CVE-2026-66794: A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker,</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b057719a6ed8ddc21077</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T15:17:27.253Z</news:publication_date>
      <news:title>CVE-2026-10059: A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can expl</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/9005e189dda256218b16</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T12:16:49.090Z</news:publication_date>
      <news:title>CVE-2026-86184: Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to aut</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/91ef10109d1e84ab67ad</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T12:16:46.790Z</news:publication_date>
      <news:title>CVE-2026-10196: The Mail Mint – Email Marketing, Newsletter, Email Automation &amp; WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all v</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/eb4f571db53ff901a91d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T01:16:49.053Z</news:publication_date>
      <news:title>CVE-2026-66786: A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/ca0abf196797b94f628d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T01:16:48.910Z</news:publication_date>
      <news:title>CVE-2026-53671: PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstract transformer in prevail trea</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/75b689603cff86071fbc</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T21:17:23.190Z</news:publication_date>
      <news:title>CVE-2025-67039: An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/f21d4b358dac5760d805</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T21:17:22.653Z</news:publication_date>
      <news:title>CVE-2025-67038: An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user&apos;s authentication fails. T</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/3f1a7c064efbda0f5fbe</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T20:45:04.290Z</news:publication_date>
      <news:title>CVE-2026-69502: Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/55d8c097940381ca0ef3</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T13:45:35.430Z</news:publication_date>
      <news:title>CVE-2019-3773: Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (X</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/8e04c97c13a1ece67de8</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T13:19:54.190Z</news:publication_date>
      <news:title>CVE-2026-46595: Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than pub</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/46408ca908c07270ef14</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T13:19:52.127Z</news:publication_date>
      <news:title>CVE-2026-45411: vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async ge</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/5a523206528f0b3f546d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T13:19:51.380Z</news:publication_date>
      <news:title>CVE-2026-44005: vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2&apos;s bridge exposes mutable proxies for real host-realm intrinsic prototypes and</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/653ccf7f9f83e2dc5e91</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T13:19:49.600Z</news:publication_date>
      <news:title>CVE-2026-42508: Previously, a revoked &apos;SignatureKey&apos; belonging to a CA was not correctly checked for revocation. Now, both the &apos;key&apos; and &apos;key.SignatureKey&apos; are checke</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/9c5f73ab8a654174ca93</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T13:19:36.840Z</news:publication_date>
      <news:title>CVE-2026-39832: When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/a86e245400b9ee24396b</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T13:19:35.617Z</news:publication_date>
      <news:title>CVE-2026-39830: A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection&apos;s read loop. The blocked goro</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b8c51aa2faac5c70b9a9</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T13:19:25.650Z</news:publication_date>
      <news:title>CVE-2026-33937: Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-p</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/297e678e7ef6e45f6786</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T13:18:55.120Z</news:publication_date>
      <news:title>CVE-2026-33228: flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed J</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/a3875d761017a5ff32d5</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T13:18:48.943Z</news:publication_date>
      <news:title>CVE-2026-33186: gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of t</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/90600e0b4f2176580f85</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T13:18:39.603Z</news:publication_date>
      <news:title>CVE-2026-29063: Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutab</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/166368e5b024a5374276</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T13:17:56.847Z</news:publication_date>
      <news:title>CVE-2025-61140: The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/f7877695bc504502b4ea</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T13:17:52.707Z</news:publication_date>
      <news:title>CVE-2025-10263: Arm C1-Ultra, C1-Premium, Neoverse V3 &amp; V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d0808b8ef96f2db855be</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T18:17:28.207Z</news:publication_date>
      <news:title>CVE-2026-71474: A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.opensh</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/e26c5250a4754390791b</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T04:18:05.100Z</news:publication_date>
      <news:title>CVE-2026-85048: Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute ar</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/2b9e8a609fda63269ead</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T21:16:50.723Z</news:publication_date>
      <news:title>CVE-2026-67281: RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/9020a01f1155fb34c68f</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T14:17:23.587Z</news:publication_date>
      <news:title>CVE-2026-76139: A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its a</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/1345e657ee9ac2db5376</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T16:17:22.350Z</news:publication_date>
      <news:title>CVE-2026-54100: A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows w</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/62a0164495f425d7d988</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T02:17:19.417Z</news:publication_date>
      <news:title>CVE-2026-85179: Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/350390eac2e9128920c5</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T02:17:19.897Z</news:publication_date>
      <news:title>CVE-2026-84233: A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workf</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/ba4b48c4b06f6eebea5a</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:07:41.340Z</news:publication_date>
      <news:title>CVE-2026-40987: A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) wi</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/76161893afb285c227af</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T18:17:28.630Z</news:publication_date>
      <news:title>CVE-2026-71846: A flaw was found in insights-client. The component&apos;s ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permi</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/1a895a42e49def3f064e</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T18:17:28.350Z</news:publication_date>
      <news:title>CVE-2026-71475: A flaw was found in insights-client. A compromised managed cluster, referred to as a &apos;spoke&apos;, can inject unencoded data into the Insights API URL path</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/dc0d4d51bee1ad5d814a</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T18:17:28.070Z</news:publication_date>
      <news:title>CVE-2026-71468: A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user&apos;s bearer token f</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/3973c202a0a2ea7622b2</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T18:17:27.930Z</news:publication_date>
      <news:title>CVE-2026-64927: A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the syste</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/960cc0905dd9d11c8e8e</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T03:17:41.637Z</news:publication_date>
      <news:title>CVE-2026-55421: Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 00b7c3c, the endpoint accepts user-supplied file</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/de4a71e35c6a22ee91be</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T22:17:17.573Z</news:publication_date>
      <news:title>CVE-2026-55985: The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/134926b4954d2da60a3b</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T12:16:46.923Z</news:publication_date>
      <news:title>CVE-2026-12843: The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verify</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/416c159c117b570e940f</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T11:16:46.123Z</news:publication_date>
      <news:title>CVE-2026-86175: NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view p</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/c210c49b89fc5efb6870</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T20:12:57.510Z</news:publication_date>
      <news:title>CVE-2026-47859: RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/9ee374453d68a91a446d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-03T23:17:19.400Z</news:publication_date>
      <news:title>CVE-2026-18330: A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/04f332d10faf424aed2e</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T12:00:00.000Z</news:publication_date>
      <news:title>DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/48c5d9fb4751086e1315</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T08:29:18.000Z</news:publication_date>
      <news:title>OpenAI’s new Astra model can code better. But here’s why its cybersecurity skills matter as much - The Indian Express</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/95df76ef3a0bdb988013</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T15:20:19.000Z</news:publication_date>
      <news:title>PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/041d5da0437cd240691e</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T20:14:47.000Z</news:publication_date>
      <news:title>Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/ecfb3b986a6f1bd0f800</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T16:05:08.000Z</news:publication_date>
      <news:title>Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/585d9fe2a7e2f9ef824b</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T14:51:13.000Z</news:publication_date>
      <news:title>New Ted Backdoor Hides Inside Victims&apos; Own HAProxy Builds to Intercept Web Traffic</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/0295a24d122b23f23022</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T10:00:00.000Z</news:publication_date>
      <news:title>Why judgment is emerging as cybersecurity’s defining skill</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/f712d299703d3d2133e9</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T08:48:45.000Z</news:publication_date>
      <news:title>Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/e20db26e269fed5e5d8d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T14:17:02.000Z</news:publication_date>
      <news:title>Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers&apos; Data It Said Was Deleted</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b502cf285b684016b251</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T11:11:50.000Z</news:publication_date>
      <news:title>OpenAI admits it didn&apos;t disclose rogue AI wiki hijacking incident</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/913086de2e850433223c</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T07:35:14.000Z</news:publication_date>
      <news:title>Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/419d99708768274f9d2f</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T07:31:53.000Z</news:publication_date>
      <news:title>Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/a1ae014aee86bc4521c5</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T13:22:01.000Z</news:publication_date>
      <news:title>New CrowdStrike &apos;FalconFlank&apos; zero-day grants SYSTEM privileges</news:title>
    </news:news>
  </url>
</urlset>