<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://cyberdeltaforce.ai/news/5100955b13d08b6afea0</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T05:17:06.393Z</news:publication_date>
      <news:title>CVE-2026-82616: A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The m</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/f20f035f665dd3858f36</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T04:18:02.447Z</news:publication_date>
      <news:title>CVE-2026-82266: Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as supe</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/68c099dfa6167c794edf</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T04:18:02.160Z</news:publication_date>
      <news:title>CVE-2026-82078: An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d238330b327b85f8916b</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T04:18:01.990Z</news:publication_date>
      <news:title>CVE-2026-81578: An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthentic</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b9c20b331a8b80adc56c</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T04:18:01.510Z</news:publication_date>
      <news:title>CVE-2026-50152: Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor sub</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/252efaa7c1db10779811</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T04:18:01.370Z</news:publication_date>
      <news:title>CVE-2026-3627: IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the a</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d4c2c8dcb2245e0f4726</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T04:18:00.997Z</news:publication_date>
      <news:title>CVE-2026-37004: BerriAI litellm &lt;=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/4cae973843c423dc20e5</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T04:18:00.830Z</news:publication_date>
      <news:title>CVE-2026-19295: IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/67d4fca7ed7bd1abce9c</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T04:18:00.670Z</news:publication_date>
      <news:title>CVE-2026-19286: IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/bb279a0f47f649af8659</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T10:16:49.963Z</news:publication_date>
      <news:title>CVE-2026-49003: Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyz</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/036552fa7feee6ca9ca2</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T10:16:46.663Z</news:publication_date>
      <news:title>CVE-2026-12965: The Super Store Finder WordPress plugin before 7.11 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, al</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/afd60b4311ca7ec3a6ea</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T00:16:41.630Z</news:publication_date>
      <news:title>CVE-2026-82593: A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LT</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/9d54d5248fa0f9547aea</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T03:16:52.100Z</news:publication_date>
      <news:title>CVE-2026-82452: rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in the</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/4b7ebf519bcea553c869</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T03:16:51.370Z</news:publication_date>
      <news:title>CVE-2026-75865: The WPLP Cookie Consent – Cookie Banner &amp; Consent Management for GDPR, CCPA &amp; Google Consent Mode plugin for WordPress is vulnerable to arbitrary file</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/54e04ccf8876dcd3c839</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T03:16:50.937Z</news:publication_date>
      <news:title>CVE-2026-67394: A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/7830ec678a60b6626608</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T18:08:14.137Z</news:publication_date>
      <news:title>CVE-2019-25029: In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerab</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/a9f149c05702da655095</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T09:17:08.453Z</news:publication_date>
      <news:title>CVE-2026-82874: ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of toolj</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/1e6f4f31263346a758d1</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T09:17:08.160Z</news:publication_date>
      <news:title>CVE-2026-82872: ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user&apos;s workspace before performing ToolJet DB table</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/f8270a07ab1a92d09f99</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T09:17:07.863Z</news:publication_date>
      <news:title>CVE-2026-82870: ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, al</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/55ef072f7b38e770e7ea</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T09:17:06.353Z</news:publication_date>
      <news:title>CVE-2026-82860: @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/72dd3387316bb0623093</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T09:17:06.210Z</news:publication_date>
      <news:title>CVE-2026-82859: hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypa</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/7111d61314609fb9b64b</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T09:17:06.067Z</news:publication_date>
      <news:title>CVE-2026-82858: @hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliati</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/6a8d74b49be80d84aee9</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T09:17:05.920Z</news:publication_date>
      <news:title>CVE-2026-82857: hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/0788aaa67d736f4e41b5</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T09:17:05.780Z</news:publication_date>
      <news:title>CVE-2026-82856: @hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers ca</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/cba312d620b2a2301611</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T09:17:05.610Z</news:publication_date>
      <news:title>CVE-2026-82855: @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that all</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/298a4834eb374d90f7db</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T09:17:05.463Z</news:publication_date>
      <news:title>CVE-2026-82854: Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom e</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/9a58fb054c6b6440cdc6</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T09:17:03.130Z</news:publication_date>
      <news:title>CVE-2026-19410: An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/abf6c7ccfec09e61b459</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T23:17:08.303Z</news:publication_date>
      <news:title>CVE-2026-82592: A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk F</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b69a12005faf5ef8a5e9</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T13:16:56.267Z</news:publication_date>
      <news:title>CVE-2026-82542: A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Rout</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/7fb4afdf94489a0e0fe4</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T02:16:58.397Z</news:publication_date>
      <news:title>CVE-2026-55511: Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/3465512c6e16ad552aab</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T02:16:58.267Z</news:publication_date>
      <news:title>CVE-2026-55378: JS Recon is a JavaScript enumeration and SAST tool. From 1.2.1-beta.1 until 1.3.1-beta.2, the PR Branch Checker workflow in .github/workflows/pr_check</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/68c8bd138ea8e1df1e0f</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T20:30:14.457Z</news:publication_date>
      <news:title>CVE-2026-67341: ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with d</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/97f55ab62aac0aa9b5d5</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T20:30:14.457Z</news:publication_date>
      <news:title>CVE-2026-67342: ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoin</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/f84e2f565607efe977d9</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T20:25:28.573Z</news:publication_date>
      <news:title>CVE-2026-67289: FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAd</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/64c80ce3dac504628f64</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T20:25:28.573Z</news:publication_date>
      <news:title>CVE-2026-66418: OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML a</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/f23156afdbe4e843b93b</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T20:25:28.573Z</news:publication_date>
      <news:title>CVE-2026-66421: OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript i</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/bb8074bccb889205057c</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T20:25:28.573Z</news:publication_date>
      <news:title>CVE-2026-66402: FreeRDP before 3.29.0 (affected versions &lt;= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b0f9ffbf12acf48baa32</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T20:25:28.573Z</news:publication_date>
      <news:title>CVE-2026-67305: FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTE</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/73ca791d3024d151c5fd</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T20:25:28.573Z</news:publication_date>
      <news:title>CVE-2026-67324: GitPython 3.1.50 fails to recognize joined short-option forms such as -u (the short form of --upload-pack= ) when enforcing its default u</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/9a9604c19088e658b51d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T17:17:33.853Z</news:publication_date>
      <news:title>CVE-2025-49796: A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw al</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/c5ff9225f1750b6a5959</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T17:17:33.377Z</news:publication_date>
      <news:title>CVE-2025-49794: A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/479aef1da6cf0fcdefe0</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T05:16:58.407Z</news:publication_date>
      <news:title>CVE-2026-15980: The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing author</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/bac66d79aa681db7633b</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T19:33:11.197Z</news:publication_date>
      <news:title>CVE-2026-38709: TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/3d9eefd09ce058fc2cab</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T19:33:11.197Z</news:publication_date>
      <news:title>CVE-2026-67822: Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses spr</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/a6b85ed97161da1bc17c</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T19:33:11.197Z</news:publication_date>
      <news:title>CVE-2025-69946: SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_i</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/a5a51cc9ae3b0e7a8495</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T19:33:11.197Z</news:publication_date>
      <news:title>CVE-2026-51785: An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/ef14ff6ada8c727d1377</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T07:17:44.937Z</news:publication_date>
      <news:title>CVE-2026-67271: Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS. An unauthenticated attacker with remote access could potentially exp</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/5fbf607b9260d778a7bc</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T07:17:44.743Z</news:publication_date>
      <news:title>CVE-2026-58574: Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restrict</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/84139ea913516dfbe986</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T01:16:49.563Z</news:publication_date>
      <news:title>CVE-2026-77956: Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitra</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b82e6d1eeb0c51eb21bc</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T23:16:35.650Z</news:publication_date>
      <news:title>CVE-2026-83524: A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the func</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/bc00f576724e159a8878</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T23:16:35.460Z</news:publication_date>
      <news:title>CVE-2026-82971: A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/c7cc823cf759bb1b006b</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T18:17:17.633Z</news:publication_date>
      <news:title>CVE-2026-4480: A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the &quot;print</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b10c01b2a901161ad10e</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T05:17:06.217Z</news:publication_date>
      <news:title>CVE-2026-82615: A vulnerability has been found in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function Customer::find_phone of the file /</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/fc620445b35bc652fb37</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T05:17:04.020Z</news:publication_date>
      <news:title>CVE-2026-82614: A flaw has been found in itsourcecode Online Medicine Delivery System 1.0. This vulnerability affects the function loadResultList of the file /index.p</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/4296707cdc7baca501c4</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T19:17:29.543Z</news:publication_date>
      <news:title>CVE-2026-81636: Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated client to bypass the configure</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/61bdc4ff552d8342da6c</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T19:17:29.220Z</news:publication_date>
      <news:title>CVE-2026-80223: Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to receive another tenant&apos;s records</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/4eab2203313e6175bb54</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T04:18:02.317Z</news:publication_date>
      <news:title>CVE-2026-82217: In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI &quot;Agent Mode&quot; file-change tools (writeFileContent, suggestFileContent, and the</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/e004e3d7b8eca3624f7a</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T04:18:01.850Z</news:publication_date>
      <news:title>CVE-2026-75118: A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient bounds c</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/6737847ae5573ffe3abd</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T04:18:00.047Z</news:publication_date>
      <news:title>CVE-2026-16821: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/a48d4248c9d53b94f71b</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T23:16:35.180Z</news:publication_date>
      <news:title>CVE-2026-22244: OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/79261a85aedea20e9f47</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T10:16:48.890Z</news:publication_date>
      <news:title>CVE-2026-15573: A flaw was found in Keycloak&apos;s Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does no</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/5fb2f886e55d13a9d49f</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T10:16:48.383Z</news:publication_date>
      <news:title>CVE-2026-14380: DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle&apos;s Profil</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/3e8b3cf5160ca3ad3446</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T04:17:28.980Z</news:publication_date>
      <news:title>CVE-2026-82724: Incorrect Authorization vulnerability in ash-project ash_phoenix invokes the SubdomainHook authorization callback with a nil tenant, so tenant-scoped</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d2bb3b4a3b71665a542d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T04:17:28.777Z</news:publication_date>
      <news:title>CVE-2026-82613: A vulnerability was detected in itsourcecode Online Medicine Delivery System 1.0. This affects the function loadResultList of the file /index.php?q=pr</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/2c2e2ce2b172129f5889</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T04:17:28.543Z</news:publication_date>
      <news:title>CVE-2026-82612: A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function loadResultList</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/96bbb372305f279647fc</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T04:17:28.317Z</news:publication_date>
      <news:title>CVE-2026-82611: A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function Customer::cusAuthen</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/3c0c6a33d0c51d55f548</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T04:17:26.273Z</news:publication_date>
      <news:title>CVE-2026-82610: A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. Affected is the function Employee::employeeAuthentication of</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/ca8a26c19fae9b09e5c0</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T04:17:14.177Z</news:publication_date>
      <news:title>CVE-2026-6893: A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/361ce2c176f5ac68dc18</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T04:17:06.600Z</news:publication_date>
      <news:title>CVE-2026-15816: A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory with</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/2d9cadfaad40f77ee48c</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T00:16:41.980Z</news:publication_date>
      <news:title>CVE-2026-82595: A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the co</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/a949ec0cd7b15d6a4b78</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T14:17:04.193Z</news:publication_date>
      <news:title>CVE-2026-82642: Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configurat</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/f773a3436e227bde3c35</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T14:17:04.020Z</news:publication_date>
      <news:title>CVE-2026-82641: keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/fb665c756a8ac441e0e7</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T14:17:03.750Z</news:publication_date>
      <news:title>CVE-2026-82639: NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain th</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/03de0ce83b3da2c59537</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T14:17:03.610Z</news:publication_date>
      <news:title>CVE-2026-82638: jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/cf4cefe915a681c80b22</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T14:17:03.310Z</news:publication_date>
      <news:title>CVE-2026-82636: Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, becaus</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/82f24e0e463acfdb57e8</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T07:17:21.673Z</news:publication_date>
      <news:title>CVE-2026-80721: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: ensure no dangling hcon references in iso_conn After iso_conn_de</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/1345e657ee9ac2db5376</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T03:16:49.037Z</news:publication_date>
      <news:title>CVE-2026-54100: A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows w</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/5eab2ecb116941f8dc83</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T03:16:42.307Z</news:publication_date>
      <news:title>CVE-2026-77850: Stored Cross-site Scripting vulnerability in ash-project ash_admin executes attacker-supplied record content as script in an administrator&apos;s browser.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/e71bc2f0656fafcdb023</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T03:16:42.133Z</news:publication_date>
      <news:title>CVE-2026-75757: Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/0ae78f989eefd64bba13</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T03:16:41.837Z</news:publication_date>
      <news:title>CVE-2026-5260: A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA k</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/7e95b9102c3ead6627af</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T03:16:40.973Z</news:publication_date>
      <news:title>CVE-2026-42013: A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectl</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/3809e8c8da7cbb4de688</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T03:16:40.080Z</news:publication_date>
      <news:title>CVE-2026-42010: A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL cha</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/ef647bbfb8949184bca3</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T20:25:28.573Z</news:publication_date>
      <news:title>CVE-2026-67300: FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIF</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/1014c927d7ca5f38a075</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T20:25:28.573Z</news:publication_date>
      <news:title>CVE-2026-67322: GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/a1ebc0adc81d662cb5f3</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T17:17:28.267Z</news:publication_date>
      <news:title>CVE-2024-10963: A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/8367ae4dea00e619903f</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T16:16:43.667Z</news:publication_date>
      <news:title>CVE-2026-82549: A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such m</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/98a2be2b3e49a4badda1</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T16:16:42.623Z</news:publication_date>
      <news:title>CVE-2026-78699: Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b39dd327916314bc930f</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T20:17:06.923Z</news:publication_date>
      <news:title>CVE-2026-5674: A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploit</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/22a410db65eb2b36bb71</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T15:16:46.310Z</news:publication_date>
      <news:title>CVE-2026-82655: Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated a</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/f5b2a5bd4f5b008069d6</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T15:16:46.173Z</news:publication_date>
      <news:title>CVE-2026-82654: SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/315417fc3f9db8554920</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T15:16:46.033Z</news:publication_date>
      <news:title>CVE-2026-82653: SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are inte</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/145a05a2c5c654987caa</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T15:16:45.470Z</news:publication_date>
      <news:title>CVE-2026-82649: SiYuan Windows installer before version 3.8.1 (affected versions &gt;= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS ins</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/12c7fa687d2496e66c8d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T15:16:45.300Z</news:publication_date>
      <news:title>CVE-2026-82648: WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses w</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/818c685f86639b9e7a9f</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T15:16:44.863Z</news:publication_date>
      <news:title>CVE-2026-82645: AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Sup</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/44134d706c3249b842ff</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T15:16:44.727Z</news:publication_date>
      <news:title>CVE-2026-82644: WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 ot</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/cd280ca8720b03dbb2ca</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-30T14:17:03.890Z</news:publication_date>
      <news:title>CVE-2026-82640: browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attacker</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/563573c9d8aa09106d51</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T09:17:07.260Z</news:publication_date>
      <news:title>CVE-2026-82866: @pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without val</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/c4d1c8e1b0dbe223654d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T09:17:04.093Z</news:publication_date>
      <news:title>CVE-2026-82662: Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/ebd8af7c27bac074cc3b</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T20:25:28.573Z</news:publication_date>
      <news:title>CVE-2026-67306: FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder functions planar_decompress_plan</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/f1ae658b4848330dcd90</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T01:16:45.533Z</news:publication_date>
      <news:title>CVE-2025-0604: A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate t</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/38c4c0a1fcb82a74931b</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T15:17:08.210Z</news:publication_date>
      <news:title>CVE-2025-54771: A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorr</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/7ee308925fc2c05a9741</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T15:17:05.697Z</news:publication_date>
      <news:title>CVE-2025-11568: A data corruption vulnerability has been identified in the luksmeta utility when used with the LUKS1 disk encryption format. An attacker with the nece</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/6c7418fd945161b9d18d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-01T14:00:00.000Z</news:publication_date>
      <news:title>Financially Motivated Threat Actor BREEZE COMET Targets Brazil</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/3a6ab580ca7a940ac550</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T20:00:34.000Z</news:publication_date>
      <news:title>The Coding-Agent Trap: When a &quot;Free&quot; LLM Endpoint Is the Adversary, (Mon, Aug 31st)</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/29a0ccea62b58a3c052d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T13:38:28.000Z</news:publication_date>
      <news:title>Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/a2443b02c1fdfa2dee1c</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T12:58:42.000Z</news:publication_date>
      <news:title>31th August – Threat Intelligence Report</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/c8fa9978201c5cd4f7d3</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T14:14:06.000Z</news:publication_date>
      <news:title>Hackers Hide ValleyRAT Backdoor Inside Adware Targeting Users in China and India - CyberSecurityNews</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/928ee9d2ed34daf55d9a</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T18:51:04.000Z</news:publication_date>
      <news:title>Microsoft warns of TerminalFix attacks deploying reverse tunnels</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/4b6920da8bbf1cd2b1ad</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T12:11:58.000Z</news:publication_date>
      <news:title>Anthropic Warns Claude Users of Infostealer Malware Infections</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/fff1e5f5694a5e951bdc</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T21:39:01.000Z</news:publication_date>
      <news:title>McKesson copes with fallout from data theft extortion attack</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/ec29f508a16f6de0458b</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T11:31:47.000Z</news:publication_date>
      <news:title>Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/4fb28834c77047c0b102</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T07:56:53.000Z</news:publication_date>
      <news:title>DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d91b37f5133c18c32642</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-08-31T14:00:10.000Z</news:publication_date>
      <news:title>File servers are here to stay. Here’s how to manage them securely</news:title>
    </news:news>
  </url>
</urlset>