<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>2026 - Sn1perSecurity</title>
	<atom:link href="https://sn1persecurity.com/wordpress/tag/2026/feed/" rel="self" type="application/rss+xml" />
	<link>https://sn1persecurity.com/wordpress</link>
	<description>Get an attacker&#039;s view of your organization with our all-in-one offensive security platform</description>
	<lastBuildDate>Mon, 03 Aug 2026 17:36:26 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://sn1persecurity.com/wordpress/wp-content/uploads/2023/03/favoriteiconsniper.png</url>
	<title>2026 - Sn1perSecurity</title>
	<link>https://sn1persecurity.com/wordpress</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">197797428</site>	<item>
		<title>CVE-2026-42533: NGINX map Directive Heap Buffer Overflow &#8211; Advisory + Nuclei Detection</title>
		<link>https://sn1persecurity.com/wordpress/cve-2026-42533-nginx-map-heap-overflow-detection-with-sn1per/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cve-2026-42533-nginx-map-heap-overflow-detection-with-sn1per</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Mon, 03 Aug 2026 17:08:57 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Bug Bounties]]></category>
		<category><![CDATA[CVE's]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Vulnerability Scanning]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[aslr-bypass]]></category>
		<category><![CDATA[cve-2026-42533]]></category>
		<category><![CDATA[heap-buffer-overflow]]></category>
		<category><![CDATA[memory-corruption]]></category>
		<category><![CDATA[nginx-map-directive]]></category>
		<category><![CDATA[nginx-security]]></category>
		<category><![CDATA[nginx-vulnerability]]></category>
		<category><![CDATA[nuclei-template]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<category><![CDATA[web-server-security]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/cve-2026-42533-nginx-map-heap-overflow-detection-with-sn1per/</guid>

					<description><![CDATA[<p>CVE-2026-42533 is a critical heap buffer overflow in the NGINX script engine reached through the map directive, with weaponized public exploit code that defeats ASLR. A plain-English advisory, a tested non-destructive Nuclei detection template, and the two-window version trap that makes naive scanners clear every mainline 1.31.x host as patched.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/cve-2026-42533-nginx-map-heap-overflow-detection-with-sn1per/">CVE-2026-42533: NGINX map Directive Heap Buffer Overflow – Advisory + Nuclei Detection</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65605</post-id>	</item>
		<item>
		<title>CVE-2026-42945 (NGINX Rift): Heap Buffer Overflow in the Rewrite Module &#8211; Advisory + Nuclei Detection</title>
		<link>https://sn1persecurity.com/wordpress/cve-2026-42945-nginx-rift-heap-overflow-detection-with-sn1per/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cve-2026-42945-nginx-rift-heap-overflow-detection-with-sn1per</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Mon, 03 Aug 2026 17:08:55 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Bug Bounties]]></category>
		<category><![CDATA[CVE's]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Vulnerability Scanning]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[cve-2026-42945]]></category>
		<category><![CDATA[heap-buffer-overflow]]></category>
		<category><![CDATA[memory-corruption]]></category>
		<category><![CDATA[nginx-rift]]></category>
		<category><![CDATA[nginx-security]]></category>
		<category><![CDATA[nginx-vulnerability]]></category>
		<category><![CDATA[ngx-http-rewrite-module]]></category>
		<category><![CDATA[nuclei-template]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<category><![CDATA[unauthenticated-rce]]></category>
		<category><![CDATA[web-server-security]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/cve-2026-42945-nginx-rift-heap-overflow-detection-with-sn1per/</guid>

					<description><![CDATA[<p>CVE-2026-42945, known as NGINX Rift, is a critical heap buffer overflow in ngx_http_rewrite_module reachable from a single unauthenticated request, with exploitation reported in the wild. A plain-English advisory, a tested non-destructive Nuclei detection template, a configuration audit template for the pattern nginx -t will not warn you about, and why upgrading to 1.30.1 leaves you exposed.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/cve-2026-42945-nginx-rift-heap-overflow-detection-with-sn1per/">CVE-2026-42945 (NGINX Rift): Heap Buffer Overflow in the Rewrite Module – Advisory + Nuclei Detection</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65603</post-id>	</item>
		<item>
		<title>CVE-2026-61511: Pre-Auth Remote Code Execution in vBulletin (runMaths) &#8211; Advisory + Nuclei Detection</title>
		<link>https://sn1persecurity.com/wordpress/cve-2026-61511-vbulletin-preauth-rce-detection-with-sn1per/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cve-2026-61511-vbulletin-preauth-rce-detection-with-sn1per</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 19:54:35 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Bug Bounties]]></category>
		<category><![CDATA[CVE's]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Vulnerability Scanning]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[cve-2026-61511]]></category>
		<category><![CDATA[eval-injection]]></category>
		<category><![CDATA[forum-security]]></category>
		<category><![CDATA[nuclei-template]]></category>
		<category><![CDATA[php-rce]]></category>
		<category><![CDATA[runmaths]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<category><![CDATA[unauthenticated-rce]]></category>
		<category><![CDATA[vbulletin-rce]]></category>
		<category><![CDATA[vbulletin-security]]></category>
		<category><![CDATA[vbulletin-vulnerability]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/cve-2026-61511-vbulletin-preauth-rce-detection-with-sn1per/</guid>

					<description><![CDATA[<p>CVE-2026-61511 is a critical unauthenticated RCE in vBulletin 5.x and 6.x, caused by eval injection in the runMaths() template handler. A plain-English advisory, a tested non-destructive Nuclei detection template, the 6.x patch-level trap that hides unpatched hosts, and how to find vulnerable vBulletin at scale with Sn1per.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/cve-2026-61511-vbulletin-preauth-rce-detection-with-sn1per/">CVE-2026-61511: Pre-Auth Remote Code Execution in vBulletin (runMaths) – Advisory + Nuclei Detection</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65542</post-id>	</item>
		<item>
		<title>CVE-2026-50522: Unauthenticated Deserialization RCE in Microsoft SharePoint Server &#8211; Advisory + Nuclei Detection</title>
		<link>https://sn1persecurity.com/wordpress/cve-2026-50522-sharepoint-rce-detection-with-sn1per/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cve-2026-50522-sharepoint-rce-detection-with-sn1per</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 20:50:20 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Bug Bounties]]></category>
		<category><![CDATA[CVE's]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Vulnerability Scanning]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[cve-2026-50522]]></category>
		<category><![CDATA[deserialization]]></category>
		<category><![CDATA[machine-key-theft]]></category>
		<category><![CDATA[nuclei-template]]></category>
		<category><![CDATA[pwn2own]]></category>
		<category><![CDATA[sharepoint-deserialization]]></category>
		<category><![CDATA[sharepoint-rce]]></category>
		<category><![CDATA[sharepoint-security]]></category>
		<category><![CDATA[sharepoint-vulnerability]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<category><![CDATA[unauthenticated-rce]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/cve-2026-50522-sharepoint-rce-detection-with-sn1per/</guid>

					<description><![CDATA[<p>CVE-2026-50522 is a critical, actively-exploited unauthenticated RCE in on-prem Microsoft SharePoint Server (2016, 2019, Subscription Edition). A plain-English advisory, a ready-to-run non-destructive Nuclei detection template, remediation with machine-key rotation, and how to detect vulnerable SharePoint at scale with Sn1per.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/cve-2026-50522-sharepoint-rce-detection-with-sn1per/">CVE-2026-50522: Unauthenticated Deserialization RCE in Microsoft SharePoint Server – Advisory + Nuclei Detection</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65475</post-id>	</item>
		<item>
		<title>wp2shell (CVE-2026-63030): Unauthenticated Pre-Auth RCE in WordPress Core &#8211; Advisory + Nuclei Detection</title>
		<link>https://sn1persecurity.com/wordpress/wp2shell-cve-2026-63030-wordpress-rce-detection-with-sn1per/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=wp2shell-cve-2026-63030-wordpress-rce-detection-with-sn1per</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Sat, 18 Jul 2026 19:00:36 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Bug Bounties]]></category>
		<category><![CDATA[CVE's]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[Vulnerability Scanning]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[cve-2026-60137]]></category>
		<category><![CDATA[cve-2026-63030]]></category>
		<category><![CDATA[nuclei-template]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<category><![CDATA[unauthenticated-rce]]></category>
		<category><![CDATA[wordpress-rce]]></category>
		<category><![CDATA[wordpress-security]]></category>
		<category><![CDATA[wordpress-vulnerability]]></category>
		<category><![CDATA[wp2shell]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/wp2shell-cve-2026-63030-wordpress-rce-detection-with-sn1per/</guid>

					<description><![CDATA[<p>wp2shell (CVE-2026-63030) is an unauthenticated pre-auth RCE in WordPress Core 6.9.0-6.9.4 and 7.0.0-7.0.1. A plain-English advisory, a ready-to-run Nuclei detection template, remediation, and how to detect affected WordPress at scale with Sn1per.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/wp2shell-cve-2026-63030-wordpress-rce-detection-with-sn1per/">wp2shell (CVE-2026-63030): Unauthenticated Pre-Auth RCE in WordPress Core – Advisory + Nuclei Detection</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65281</post-id>	</item>
		<item>
		<title>Network and Subnet Discovery: Map Your Internal Attack Surface with Sn1per Pro 2026</title>
		<link>https://sn1persecurity.com/wordpress/network-subnet-discovery/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=network-subnet-discovery</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Sun, 12 Jul 2026 13:33:26 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[asset-discovery]]></category>
		<category><![CDATA[attack-surface-management]]></category>
		<category><![CDATA[connected-devices]]></category>
		<category><![CDATA[internal-attack-surface]]></category>
		<category><![CDATA[network-discovery]]></category>
		<category><![CDATA[network-subnet-discovery]]></category>
		<category><![CDATA[self-hosted]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<category><![CDATA[subnet-scanning]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/network-subnet-discovery/</guid>

					<description><![CDATA[<p>Discover live hosts, open ports, services, and connected devices across your internal subnets with Sn1per Professional 2026 - a self-hosted, automated network and subnet discovery tool you run from the CLI or a web dashboard.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/network-subnet-discovery/">Network and Subnet Discovery: Map Your Internal Attack Surface with Sn1per Pro 2026</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65161</post-id>	</item>
		<item>
		<title>Active Reconnaissance: Techniques, Tools and Workflow (2026)</title>
		<link>https://sn1persecurity.com/wordpress/active-reconnaissance/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=active-reconnaissance</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Sat, 04 Jul 2026 18:39:36 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Bug Bounties]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Red Team]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[active-reconnaissance]]></category>
		<category><![CDATA[attack-surface-management]]></category>
		<category><![CDATA[bug-bounty]]></category>
		<category><![CDATA[fingerprinting]]></category>
		<category><![CDATA[NMap]]></category>
		<category><![CDATA[offensive-security]]></category>
		<category><![CDATA[port-scanning]]></category>
		<category><![CDATA[reconnaissance]]></category>
		<category><![CDATA[red-team]]></category>
		<category><![CDATA[sn1per]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/active-reconnaissance/</guid>

					<description><![CDATA[<p>Active reconnaissance explained for 2026 - port scanning, service and technology fingerprinting, screenshots and endpoint discovery - the tools, the scope rules, and how Sn1per automates it safely.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/active-reconnaissance/">Active Reconnaissance: Techniques, Tools and Workflow (2026)</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65004</post-id>	</item>
		<item>
		<title>Subdomain Enumeration: The Complete 2026 Guide (Passive, Active and Brute Force)</title>
		<link>https://sn1persecurity.com/wordpress/subdomain-enumeration/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=subdomain-enumeration</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Sat, 04 Jul 2026 18:39:32 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Bug Bounties]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[asset-discovery]]></category>
		<category><![CDATA[attack-surface-management]]></category>
		<category><![CDATA[bug-bounty]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[OSINT]]></category>
		<category><![CDATA[owasp-amass]]></category>
		<category><![CDATA[reconnaissance]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[subdomain-enumeration]]></category>
		<category><![CDATA[subdomains]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/subdomain-enumeration/</guid>

					<description><![CDATA[<p>How to enumerate subdomains in 2026 - passive sources, active brute force and permutation, DNS resolution, virtual hosts and takeover checks - with the best open-source tools and how Sn1per runs them all.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/subdomain-enumeration/">Subdomain Enumeration: The Complete 2026 Guide (Passive, Active and Brute Force)</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65002</post-id>	</item>
		<item>
		<title>The Reconnaissance Methodology: A Phased Recon Workflow for Bug Bounty, Red Team and EASM (2026)</title>
		<link>https://sn1persecurity.com/wordpress/reconnaissance-methodology/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=reconnaissance-methodology</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Sat, 04 Jul 2026 18:39:28 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Bug Bounties]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Red Team]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[attack-surface-management]]></category>
		<category><![CDATA[bug-bounty]]></category>
		<category><![CDATA[easm]]></category>
		<category><![CDATA[offensive-security]]></category>
		<category><![CDATA[OSINT]]></category>
		<category><![CDATA[recon]]></category>
		<category><![CDATA[reconnaissance]]></category>
		<category><![CDATA[reconnaissance-methodology]]></category>
		<category><![CDATA[red-team]]></category>
		<category><![CDATA[sn1per]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/reconnaissance-methodology/</guid>

					<description><![CDATA[<p>A phased reconnaissance methodology for bug bounty, red team and external attack surface management. Every recon stage from OSINT to reporting - and how Sn1per automates the whole chain.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/reconnaissance-methodology/">The Reconnaissance Methodology: A Phased Recon Workflow for Bug Bounty, Red Team and EASM (2026)</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">65000</post-id>	</item>
		<item>
		<title>Continuous Penetration Testing (PTaaS): Beyond the Once-a-Year Pentest</title>
		<link>https://sn1persecurity.com/wordpress/continuous-penetration-testing/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=continuous-penetration-testing</link>
		
		<dc:creator><![CDATA[xer0dayz]]></dc:creator>
		<pubDate>Thu, 18 Jun 2026 16:18:20 +0000</pubDate>
				<category><![CDATA[Attack Surface Management]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[2026]]></category>
		<category><![CDATA[automated penetration testing]]></category>
		<category><![CDATA[continuous-penetration-testing]]></category>
		<category><![CDATA[continuous-testing]]></category>
		<category><![CDATA[managed-penetration-testing]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[ptaas]]></category>
		<category><![CDATA[sn1per]]></category>
		<category><![CDATA[sn1per pro]]></category>
		<guid isPermaLink="false">https://sn1persecurity.com/wordpress/continuous-penetration-testing/</guid>

					<description><![CDATA[<p>The annual pentest is stale within weeks. A 2026 guide to continuous penetration testing and PTaaS - how it differs from point-in-time testing and from continuous ASM, and how to run it with Sn1per.</p>
<p>The post <a href="https://sn1persecurity.com/wordpress/continuous-penetration-testing/">Continuous Penetration Testing (PTaaS): Beyond the Once-a-Year Pentest</a> first appeared on <a href="https://sn1persecurity.com/wordpress">Sn1perSecurity</a>.</p>]]></description>
		
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">64650</post-id>	</item>
	</channel>
</rss>
