<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://cyberdeltaforce.ai/news/34f4ffb7631a9c61899b</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T04:18:32.523Z</news:publication_date>
      <news:title>CVE-2026-86165: A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a ma</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/9a9604c19088e658b51d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T04:18:23.357Z</news:publication_date>
      <news:title>CVE-2025-49796: A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw al</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/c5ff9225f1750b6a5959</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T04:18:21.540Z</news:publication_date>
      <news:title>CVE-2025-49794: A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/269f24178411f26c1569</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T10:16:43.900Z</news:publication_date>
      <news:title>CVE-2026-86124: AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplie</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d14134bce48d8f712bc1</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T10:16:43.463Z</news:publication_date>
      <news:title>CVE-2026-86121: Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by def</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/0c69396b931ad0a474fa</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T04:18:05.063Z</news:publication_date>
      <news:title>CVE-2026-83711: Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/99410d3277fa10ea25ea</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T04:18:04.943Z</news:publication_date>
      <news:title>CVE-2026-80098: Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/62b223c3276e5c178ab4</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T04:18:04.830Z</news:publication_date>
      <news:title>CVE-2026-70352: Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/9a85ebc9cdd2bfc2facb</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T04:18:04.033Z</news:publication_date>
      <news:title>CVE-2026-62916: Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b4a2bf421d6ca128f635</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T20:46:01.823Z</news:publication_date>
      <news:title>CVE-2026-64384: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/7c4baef8ec3ed59b033a</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T20:17:21.257Z</news:publication_date>
      <news:title>CVE-2025-12543: A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to pro</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/daedce18be8c316946c0</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T03:17:17.373Z</news:publication_date>
      <news:title>CVE-2026-86218: N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/6c44b1a84c387a33ca70</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T03:17:16.607Z</news:publication_date>
      <news:title>CVE-2026-75816: The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including,</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/42bc268d3eaf47716e82</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T03:17:15.540Z</news:publication_date>
      <news:title>CVE-2026-16310: The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the &apos;id&apos; paramet</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/4f88073eb47cd9419193</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T21:16:51.400Z</news:publication_date>
      <news:title>CVE-2026-86060: RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/c6b36fb39569fde91388</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T21:16:49.387Z</news:publication_date>
      <news:title>CVE-2026-67276: RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/3b6a1455ce81c1423299</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T14:17:22.977Z</news:publication_date>
      <news:title>CVE-2026-16242: A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b2f973478aa0c7330deb</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T14:17:22.187Z</news:publication_date>
      <news:title>CVE-2026-10090: A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernete</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/c4681389c3fbdb232fb4</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T09:16:48.880Z</news:publication_date>
      <news:title>CVE-2024-11080: The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/fe70be5b33445e92e6eb</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T03:17:24.303Z</news:publication_date>
      <news:title>CVE-2026-85434: MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROK</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/c2b07ee14b2df8dbb52d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T03:17:24.050Z</news:publication_date>
      <news:title>CVE-2026-85424: MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/2572b2b1770708702c61</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T20:06:02.093Z</news:publication_date>
      <news:title>CVE-2026-22752: Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Serve</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/e9fc8e113da253a699b8</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T20:02:09.230Z</news:publication_date>
      <news:title>CVE-2025-15379: A command injection vulnerability exists in MLflow&apos;s model serving container initialization code, specifically in the `_install_model_dependencies_to_</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/ac83dfcc2a03cd7e52d2</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T02:17:19.770Z</news:publication_date>
      <news:title>CVE-2026-86153: A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b0f7f55973cf7853f276</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T02:17:19.370Z</news:publication_date>
      <news:title>CVE-2026-86152: A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/f6a658d839d36e50dd0e</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T22:17:18.943Z</news:publication_date>
      <news:title>CVE-2026-86149: A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulatio</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/f5a7e2f3efaf9d963fe0</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T22:17:18.743Z</news:publication_date>
      <news:title>CVE-2026-86148: A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the compo</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d4e8b894c262c3a6e552</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T13:18:14.150Z</news:publication_date>
      <news:title>CVE-2026-86190: WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, r</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d10f9d5b6b23069207f7</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T13:18:14.000Z</news:publication_date>
      <news:title>CVE-2026-86189: WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locati</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/0c77a7036a7818220f16</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T02:17:18.930Z</news:publication_date>
      <news:title>CVE-2026-85154: WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that gra</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/ff1c7eda368e65a86578</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T22:17:17.723Z</news:publication_date>
      <news:title>CVE-2026-61884: The Tycon Systems TPDIN-Monitor-WEB2 ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/6ef70e4d024507680f61</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T19:08:35.457Z</news:publication_date>
      <news:title>CVE-2026-64393: In the Linux kernel, the following vulnerability has been resolved: ksmbd: run set info with opener credentials SMB2 SET_INFO handlers call path-bas</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/41b0d0701e026774a9dc</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T15:17:31.100Z</news:publication_date>
      <news:title>CVE-2026-73269: A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, c</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/93fb96cc6ba5acb8c6ee</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T15:17:30.963Z</news:publication_date>
      <news:title>CVE-2026-73268: A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurato</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d67f2b17e03c2e5bd3cc</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T15:17:29.240Z</news:publication_date>
      <news:title>CVE-2026-66794: A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker,</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b057719a6ed8ddc21077</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T15:17:27.253Z</news:publication_date>
      <news:title>CVE-2026-10059: A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can expl</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/9005e189dda256218b16</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T12:16:49.090Z</news:publication_date>
      <news:title>CVE-2026-86184: Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to aut</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/91ef10109d1e84ab67ad</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T12:16:46.790Z</news:publication_date>
      <news:title>CVE-2026-10196: The Mail Mint – Email Marketing, Newsletter, Email Automation &amp; WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all v</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/eb4f571db53ff901a91d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T01:16:49.053Z</news:publication_date>
      <news:title>CVE-2026-66786: A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/ca0abf196797b94f628d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T01:16:48.910Z</news:publication_date>
      <news:title>CVE-2026-53671: PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstract transformer in prevail trea</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/75b689603cff86071fbc</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T21:17:23.190Z</news:publication_date>
      <news:title>CVE-2025-67039: An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/f21d4b358dac5760d805</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T21:17:22.653Z</news:publication_date>
      <news:title>CVE-2025-67038: An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user&apos;s authentication fails. T</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/3f1a7c064efbda0f5fbe</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T20:45:04.290Z</news:publication_date>
      <news:title>CVE-2026-69502: Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/0af2b6c55a6e9e4cf5f4</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T11:18:01.910Z</news:publication_date>
      <news:title>CVE-2026-78362: The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthent</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/f21323eb1aa0ac76fd02</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T05:16:50.477Z</news:publication_date>
      <news:title>CVE-2026-86167: A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/17b0045f220f702fd7cf</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T15:17:24.813Z</news:publication_date>
      <news:title>CVE-2026-86283: MISP&apos;s UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applyin</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d0808b8ef96f2db855be</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T18:17:28.207Z</news:publication_date>
      <news:title>CVE-2026-71474: A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.opensh</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/2b9e8a609fda63269ead</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T21:16:50.723Z</news:publication_date>
      <news:title>CVE-2026-67281: RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/9020a01f1155fb34c68f</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T14:17:23.587Z</news:publication_date>
      <news:title>CVE-2026-76139: A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its a</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/00c1823a6ed25d96ab62</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T13:17:10.963Z</news:publication_date>
      <news:title>CVE-2026-86259: OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instanc</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/d72bbf58062347dba126</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T13:17:10.667Z</news:publication_date>
      <news:title>CVE-2026-86214: A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulati</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/3db89bf181a819e7799d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T13:17:10.487Z</news:publication_date>
      <news:title>CVE-2026-86213: A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b916b1531539de40865d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T13:17:10.307Z</news:publication_date>
      <news:title>CVE-2022-51009: PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can s</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/1345e657ee9ac2db5376</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T16:17:22.350Z</news:publication_date>
      <news:title>CVE-2026-54100: A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows w</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/62a0164495f425d7d988</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T02:17:19.417Z</news:publication_date>
      <news:title>CVE-2026-85179: Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/ba4b48c4b06f6eebea5a</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T18:07:41.340Z</news:publication_date>
      <news:title>CVE-2026-40987: A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) wi</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/76161893afb285c227af</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T18:17:28.630Z</news:publication_date>
      <news:title>CVE-2026-71846: A flaw was found in insights-client. The component&apos;s ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permi</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/1a895a42e49def3f064e</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T18:17:28.350Z</news:publication_date>
      <news:title>CVE-2026-71475: A flaw was found in insights-client. A compromised managed cluster, referred to as a &apos;spoke&apos;, can inject unencoded data into the Insights API URL path</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/dc0d4d51bee1ad5d814a</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T18:17:28.070Z</news:publication_date>
      <news:title>CVE-2026-71468: A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user&apos;s bearer token f</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/3973c202a0a2ea7622b2</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T18:17:27.930Z</news:publication_date>
      <news:title>CVE-2026-64927: A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the syste</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/de4a71e35c6a22ee91be</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T22:17:17.573Z</news:publication_date>
      <news:title>CVE-2026-55985: The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/134926b4954d2da60a3b</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T12:16:46.923Z</news:publication_date>
      <news:title>CVE-2026-12843: The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verify</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/416c159c117b570e940f</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T11:16:46.123Z</news:publication_date>
      <news:title>CVE-2026-86175: NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view p</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/c210c49b89fc5efb6870</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-04T20:12:57.510Z</news:publication_date>
      <news:title>CVE-2026-47859: RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/41d1194867d1e392e8fe</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T09:32:38.000Z</news:publication_date>
      <news:title>Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/041d5da0437cd240691e</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T20:14:47.000Z</news:publication_date>
      <news:title>Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/ecfb3b986a6f1bd0f800</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T16:05:08.000Z</news:publication_date>
      <news:title>Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/3e1eed6b3067c904d120</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-06T08:34:20.000Z</news:publication_date>
      <news:title>Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/e20db26e269fed5e5d8d</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T14:17:02.000Z</news:publication_date>
      <news:title>Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers&apos; Data It Said Was Deleted</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/b502cf285b684016b251</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T11:11:50.000Z</news:publication_date>
      <news:title>OpenAI admits it didn&apos;t disclose rogue AI wiki hijacking incident</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cyberdeltaforce.ai/news/419d99708768274f9d2f</loc>
    <news:news>
      <news:publication>
        <news:name>CyberDeltaForce</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-05T07:31:53.000Z</news:publication_date>
      <news:title>Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities</news:title>
    </news:news>
  </url>
</urlset>