<?xml version="1.0" encoding="UTF-8"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9"><url><loc>https://kkm-mako.com/en/blog/articles/tinymce-cve-2026-47759-47762-stored-xss-quartet/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-28T16:59:50+00:00</news:publication_date><news:title>From WordPress Editor to Admin Hijack: Four Stored-XSS in TinyMCE, CVE-2026-47759 through 47762</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/tinymce-cve-2026-47759-47762-stored-xss-quartet/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-28T16:59:32+00:00</news:publication_date><news:title>WordPress編集者から管理者を奪える、TinyMCEに4連の保存型XSS CVE-2026-47759〜47762</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/kokkai-map-viral-claude-individual-developer/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-28T16:10:02+00:00</news:publication_date><news:title>Japan's 'Kokkai-Map' Goes Viral, Built Solo with Claude Haiku 4.5</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/kokkai-map-viral-claude-individual-developer/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-28T16:09:43+00:00</news:publication_date><news:title>「国会議員マップ」とは、建設職人がClaude活用で個人開発した政治可視化サイト</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/samba-cve-2026-4408-check-password-script-rce/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-28T11:08:23+00:00</news:publication_date><news:title>Unauthenticated RCE in Samba: CVE-2026-4408 Injects Commands via %u in check password script, Patch to 4.24.3 Now</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/samba-cve-2026-4408-check-password-script-rce/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-28T11:08:04+00:00</news:publication_date><news:title>Sambaに認証なしRCE CVE-2026-4408、check password scriptの%uでコマンド注入、4.24.3へ即更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/jupyter-server-cve-2025-61669-login-open-redirect/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-28T04:25:47+00:00</news:publication_date><news:title>Phishing Redirect Flaw in Jupyter Server CVE-2025-61669: Researcher Logins In The Crosshairs</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/jupyter-server-cve-2025-61669-login-open-redirect/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-28T04:25:32+00:00</news:publication_date><news:title>Jupyter Serverにフィッシング誘導の脆弱性 CVE-2025-61669、研究者のログイン画面が標的</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/goobi-viewer-cve-2026-45083-solr-unauth-streaming/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-27T23:07:32+00:00</news:publication_date><news:title>Goobi Viewer Hit by Unauthenticated CVE-2026-45083: Digital Archives At Risk</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/goobi-viewer-cve-2026-45083-solr-unauth-streaming/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-27T23:07:16+00:00</news:publication_date><news:title>Goobi viewerに認証なし脆弱性 CVE-2026-45083、デジタルアーカイブが危機</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/pi-alert-cve-2026-44887-44888-config-injection/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-27T21:12:30+00:00</news:publication_date><news:title>Two Unauthenticated RCEs in Pi.Alert: CVE-2026-44887 / 44888 Hit Home Network Watchers</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/pi-alert-cve-2026-44887-44888-config-injection/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-27T21:12:15+00:00</news:publication_date><news:title>Pi.Alertに2件の認証なしRCE CVE-2026-44887/44888、家庭ネット監視が危機</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/gladinet-triofox-cve-2026-8362-8363-8364-unauth-rce/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-27T21:11:19+00:00</news:publication_date><news:title>Three Critical Flaws Hit Gladinet Triofox: CVE-2026-8362 / 8363 / 8364, Enterprise File Sharing At Risk</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/gladinet-triofox-cve-2026-8362-8363-8364-unauth-rce/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-27T21:11:04+00:00</news:publication_date><news:title>Gladinet Triofoxに3件の重大脆弱性 CVE-2026-8362/8363/8364、企業ファイル共有が危機</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/budibase-cve-2026-46425-five-flaws-low-code-bypass/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-27T19:13:18+00:00</news:publication_date><news:title>Budibase Hit by Five Critical Authz Flaws: CVE-2026-46425 et al., Update to v3.39.0</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/budibase-cve-2026-46425-five-flaws-low-code-bypass/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-27T19:13:02+00:00</news:publication_date><news:title>Budibaseに5件の重大脆弱性 CVE-2026-46425他、v3.39.0へ即更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/dalfox-cve-2026-45087-rest-api-unauth-rce/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-27T19:12:06+00:00</news:publication_date><news:title>XSS Scanner Dalfox Hit by Unauthenticated RCE: CVE-2026-45087 (CVSS 10.0)</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/dalfox-cve-2026-45087-rest-api-unauth-rce/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-27T19:11:50+00:00</news:publication_date><news:title>XSSスキャナーDalfoxに認証なしRCE CVE-2026-45087、v2.13.0へ即更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/free5gc-cve-2026-44315-44326-44327-44329-44330-noauth-bypass/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-27T18:17:28+00:00</news:publication_date><news:title>free5GC Hit by Five Critical Auth Bypass Flaws: CVE-2026-44315/26/27/29/30</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/free5gc-cve-2026-44315-44326-44327-44329-44330-noauth-bypass/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-27T18:17:12+00:00</news:publication_date><news:title>free5GCに5件の重大認証バイパス CVE-2026-44315他、v4.2.2へ即更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/tanstack-nx-console-supply-chain-cve-2026-45321-48027/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-27T18:16:16+00:00</news:publication_date><news:title>From TanStack to Nx Console: Chained Supply-Chain Attack CVE-2026-45321 / CVE-2026-48027</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/tanstack-nx-console-supply-chain-cve-2026-45321-48027/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-27T18:16:01+00:00</news:publication_date><news:title>TanStack→Nx Console連鎖攻撃 CVE-2026-45321/48027、npm 84版汚染がVS Code拡張へ</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/libvnc-cve-2026-44988-malicious-server-oob-write/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-27T16:08:42+00:00</news:publication_date><news:title>LibVNCClient Flaw CVE-2026-44988: Malicious VNC Server Can Hijack Your PC On Connect</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/libvnc-cve-2026-44988-malicious-server-oob-write/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-27T16:08:27+00:00</news:publication_date><news:title>LibVNCに重大脆弱性 CVE-2026-44988、悪意あるVNCサーバに接続するだけでPC乗っ取り</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/ibm-aspera-cve-2026-8175-8179-asperahttpd-bof/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-27T15:17:02+00:00</news:publication_date><news:title>IBM Aspera Hit by Two asperahttpd Buffer Overflows: CVE-2026-8175 / CVE-2026-8179</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/ibm-aspera-cve-2026-8175-8179-asperahttpd-bof/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-27T15:16:46+00:00</news:publication_date><news:title>IBM Asperaに2件のBOF脆弱性 CVE-2026-8175/8179、放送・大企業のファイル転送基盤に即パッチを</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/langflow-cve-2026-7524-tar-symlink-rce/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-27T15:15:51+00:00</news:publication_date><news:title>Critical Langflow Flaw CVE-2026-7524: TAR Symlinks Leak JWT Secret, Chain to RCE</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/langflow-cve-2026-7524-tar-symlink-rce/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-27T15:15:35+00:00</news:publication_date><news:title>Langflowに重大脆弱性 CVE-2026-7524、tarリンク悪用でJWT流出からRCEへ</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/cisa-kev-dashboard-ja/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-27T11:46:52+00:00</news:publication_date><news:title>CISA KEV Dashboard in Japanese — Browse the Actively Exploited Catalog</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/cisa-kev-dashboard-ja/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-27T11:46:35+00:00</news:publication_date><news:title>CISA KEV 日本語ダッシュボード｜攻撃中の脆弱性カタログを全件検索</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/oss-supply-chain-scanner/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-27T11:04:50+00:00</news:publication_date><news:title>OSS Supply Chain Scanner — paste package.json, requirements.txt, pyproject.toml</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/oss-supply-chain-scanner/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-27T11:04:33+00:00</news:publication_date><news:title>【無料】OSS脆弱性スキャナー｜npm/Pythonの依存を貼るだけ即チェック</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/wpcode-cve-2026-8832-author-code-injection/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-27T08:31:53+00:00</news:publication_date><news:title>WordPress WPCode patches Author-level RCE in v2.3.6, 3 million sites affected (CVE-2026-8832)</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/wpcode-cve-2026-8832-author-code-injection/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-27T08:31:38+00:00</news:publication_date><news:title>WordPress『WPCode』に編集者権限から任意コード実行の脆弱性 CVE-2026-8832、300万サイトはv2.3.6へ即更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/ibm-vulnerability-roundup-2026-05/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-27T00:30:24+00:00</news:publication_date><news:title>IBM May 2026 vulnerability roundup: WebSphere RCE and ELM authorization bypass at the center</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/ibm-vulnerability-roundup-2026-05/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-27T00:30:06+00:00</news:publication_date><news:title>IBM 2026年5月の脆弱性まとめ：WebSphere RCE と ELM 認可バイパスが中心</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/litespeed-cpanel-plugin-cve-2026-48172-kev/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-26T18:38:54+00:00</news:publication_date><news:title>LiteSpeed cPanel plugin CVE-2026-48172 actively exploited for root takeover (CISA KEV)</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/litespeed-cpanel-plugin-cve-2026-48172-kev/</loc><news:news><news:publication><news:name>まこちゃんの技術ジャーナル</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-05-26T18:38:35+00:00</news:publication_date><news:title>cPanel用LiteSpeedプラグインに最悪脆弱性、攻撃中。サーバ丸ごと乗っ取り（CVE-2026-48172）</news:title></news:news></url></urlset>