<?xml version="1.0" encoding="UTF-8"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9"><url><loc>https://kkm-mako.com/en/blog/articles/siyuan-cve-2026-56395-56397-bazaar-xss-rce/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-21T15:20:55+00:00</news:publication_date><news:title>Takeover flaw in the SiYuan note app (CVE-2026-56395): update to 3.6.1</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/siyuan-cve-2026-56395-56397-bazaar-xss-rce/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-21T15:20:38+00:00</news:publication_date><news:title>ノートアプリ『SiYuan』に乗っ取りの穴 CVE-2026-56395ほか、3.6.1へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/crawl4ai-cve-2026-56265-docker-jwt-hardcoded-key-auth-bypass/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-21T15:19:43+00:00</news:publication_date><news:title>Unauthenticated takeover flaw in AI crawler Crawl4AI (CVE-2026-56265): update to 0.8.7</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/crawl4ai-cve-2026-56265-docker-jwt-hardcoded-key-auth-bypass/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-21T15:19:26+00:00</news:publication_date><news:title>AI開発ツールCrawl4AIに認証なし乗っ取りの穴 CVE-2026-56265、0.8.7へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/prefect-cve-2026-5366-git-argument-injection-rce/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-20T18:09:38+00:00</news:publication_date><news:title>Server takeover flaw in Prefect (CVE-2026-5366): update to the latest</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/prefect-cve-2026-5366-git-argument-injection-rce/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-20T18:09:21+00:00</news:publication_date><news:title>データ基盤『Prefect』に乗っ取りの穴 CVE-2026-5366、最新版へ更新を</news:title></news:news></url><url><loc>https://kkm-mako.com/en/blog/articles/flowise-cve-2024-58351-overrideconfig-rce/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-06-20T17:13:51+00:00</news:publication_date><news:title>Unauthenticated takeover flaw in AI builder Flowise (CVE-2024-58351): Update to 2.1.4</news:title></news:news></url><url><loc>https://kkm-mako.com/blog/articles/flowise-cve-2024-58351-overrideconfig-rce/</loc><news:news><news:publication><news:name>Canarii</news:name><news:language>ja</news:language></news:publication><news:publication_date>2026-06-20T17:13:34+00:00</news:publication_date><news:title>AI構築ツール『Flowise』に乗っ取りの穴、CVE-2024-58351は2.1.4へ更新を</news:title></news:news></url></urlset>