[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 11 08:14:36 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
86ba8288 by security tracker role at 2026-08-11T07:14:29+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
 CVE-2026-8917 (Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Su ...)
-	TODO: check
+	NOT-FOR-US: ASUS
 CVE-2026-8718 (tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/ ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-8158 (The Signed Video Framework contained a buffer overflow issue  which co ...)
-	TODO: check
+	NOT-FOR-US: Axis Communication
 CVE-2026-73035 (npm-check-updates through 23.0.2, fixed in commit b554b84, contains a  ...)
 	TODO: check
 CVE-2026-73033 (Sucuri Security WordPress plugin through version 2.7.3 contains a path ...)
@@ -83,11 +83,11 @@ CVE-2026-71966 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authentic
 CVE-2026-71965 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated r ...)
 	TODO: check
 CVE-2026-6505 (The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) ra ...)
-	TODO: check
+	NOT-FOR-US: Axis Communication
 CVE-2026-6426 (A type mismatch vulnerability was found in QEMU's vhost inflight migra ...)
 	TODO: check
 CVE-2026-6181 (The Device Configuration Framework is vulnerable to an authentication  ...)
-	TODO: check
+	NOT-FOR-US: Axis Communication
 CVE-2026-69118 (Cachet through 2.4.1 contains a server-side template injection vulnera ...)
 	TODO: check
 CVE-2026-69116 (FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering an ...)
@@ -97,85 +97,85 @@ CVE-2026-69114 (Spacebar Server before commit 8d126f4 contains a cross-channel m
 CVE-2026-69112 (Hugging Face Accelerate through 1.14.0 contains a path traversal vulne ...)
 	TODO: check
 CVE-2026-66779 (Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver App ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-66778 (SAP Approuter does not sufficiently sanitize certain request headers b ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-66777 (SAP Approuter does not sufficiently validate certain incoming requests ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-66776 (SAP Approuter does not consistently enforce integrity verification on  ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-66775 (SAP Approuter does not enforce cross-site request forgery protection o ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-66774 (SAP Approuter does not consistently handle certain error conditions. A ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-66773 (A malicious or compromised OData service could disclose sensitive auth ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-66772 (SAP BusinessObjects Business Intelligence Platform (Admin Tools)  does ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-66771 (SAPUI5 allows a key user with content adaptation privileges to inject  ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-66770 (Due to an SQL Injection vulnerability in SAP Social intelligence, an a ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-66764 (Reprocess Bank Statement Items in SAP S/4HANA does not perform the nec ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-66763 (SAP BusinessObjects Business Intelligence Platform stores certain sens ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-66761 (SAP Approuter does not enforce sufficient flow control in certain func ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-66760 (SAP Approuter does not correctly validate client certificates in certa ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-63622 (A flaw was found in libvirt. A local attacker, specifically a process  ...)
 	TODO: check
 CVE-2026-5304 (An ACAP configuration file lacks input validation, which could potenti ...)
-	TODO: check
+	NOT-FOR-US: Axis Communication
 CVE-2026-5303 (The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) ra ...)
-	TODO: check
+	NOT-FOR-US: Axis Communication
 CVE-2026-58248 (SAP BusinessObjects Business Intelligence Platform (Web Intelligence)  ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-58247 (SAP ABAP Platform allows an unauthenticated user to send a specially c ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-58245 (SAP Advanced Planning and Optimization (Model Mix Planning) contains a ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-58244 (SAP Manufacturing Integration and Intelligence (MII) does not perform  ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-58243 (SAP ABAP Development Tools does not perform necessary authorization ch ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-58241 (SAP NetWeaver and ABAP Platform (Change and Transport System - Custome ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-58239 (SAP Approuter does not sufficiently validate tenant context in inbound ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-58238 (SAP Approuter does not sufficiently handle certain requests under spec ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-58237 (WebSocket of SAP Approuter does not perform sufficient authorization c ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-58236 (SAP NetWeaver Application Server ABAP and ABAP Platform allow an attac ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-58235 (SAP NetWeaver Application Server Java (Adobe Document Service) uses ou ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-58230 (SAP Approuter does not sufficiently validate certain token content und ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-4757 (A VAPIX API parameter had improper input validation which could allow  ...)
-	TODO: check
+	NOT-FOR-US: Axis Communication
 CVE-2026-48161 (react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 a ...)
 	TODO: check
 CVE-2026-48160 (react-tracked provides state usage tracking with Proxies. Between 2026 ...)
 	TODO: check
 CVE-2026-44765 (Due to a Missing Authorization Check vulnerability in SAP Manufacturin ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-44764 (Due to a Missing Authorization Check vulnerability in SAP Manufacturin ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-44763 (SAP Manufacturing Integration and Intelligence allows a privileged att ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-44762 (SAP Data Services Management Console allows an overly permissive Conte ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-44758 (SAP Manufacturing Integration and Intelligence (MII) allows an attacke ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-44401 (Typemill CMS version 2.x contains a persistent cross-site scripting vu ...)
 	TODO: check
 CVE-2026-40130 (SAP SAPSPrint Service has memory corruption vulnerabilities in the han ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-34265 (SAP NetWeaver Application Server ABAP allows an unauthenticated attack ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-24330 (A flaw was found in wildfly-core. A remote attacker, authenticated as  ...)
 	TODO: check
 CVE-2026-24329 (A flaw was found in wildfly-core. A remote user authenticated as an ad ...)
@@ -225,21 +225,21 @@ CVE-2026-18608 (A flaw was found in the Data Science Pipelines Operator (DSPO).
 CVE-2026-18348 (Missing authorization check in the upload_azure, upload_sftp, and uplo ...)
 	TODO: check
 CVE-2026-16974 (The Kirki \u2013 Freeform Page Builder, Website Builder & Customizer p ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16456 (A flaw was found in the `odh-model-controller`. An authenticated user  ...)
 	TODO: check
 CVE-2026-16053 (Zohocorp ManageEngineM365 Manager Plus and M365 Security Plus versions ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-15581 (A flaw was found in the TrustyAI Service (TAS) deployment. This vulner ...)
 	TODO: check
 CVE-2026-15467 (A flaw was found in the trustyai-service-operator's LMEvalJob controll ...)
 	TODO: check
 CVE-2026-14886 (Vault Enterprise's identity entity batch-delete endpoint is vulnerable ...)
-	TODO: check
+	NOT-FOR-US: Hashicorp products not packaged in Debian
 CVE-2026-14549 (The Ray Enterprise Translation WordPress plugin through 1.7.3 does not ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14548 (The Ray Enterprise Translation WordPress plugin through 1.7.3 does not ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14450 (A flaw was found in the MaaS API. This vulnerability allows any pod wi ...)
 	TODO: check
 CVE-2026-13717 (A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Imp ...)
@@ -247,35 +247,35 @@ CVE-2026-13717 (A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gatewa
 CVE-2026-13716 (Path traversal in server import and admin file upload in Crafty Contro ...)
 	TODO: check
 CVE-2026-12052 (The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12051 (The USB DFU class implementation in Zephyr's new (experimental) device ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11985 (On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces  ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11894 (The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send( ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11893 (The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL6 ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11812 (The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11811 (The UpdateHub over-the-air update client's start_coap_client() in subs ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11810 (The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_ ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11809 (The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2025-32736 (Cross-Site Request Forgery weaknesses in the Administrative Console of ...)
-	TODO: check
+	NOT-FOR-US: Ping Identity Corporation
 CVE-2025-30241 (Certain web interface components in affected TP-Link Aginet devices do ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2025-30240 (The affected TP-Link Aginet devices do not properly validate symbolic  ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2025-30239 (In affected TP-Link Aginet devices, use of hardcoded cryptographic key ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2025-30238 (In affected TP-Link Aginet devices, insufficient authorization validat ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2025-30237 (The affected TP-Link Aginet devicescontain a flaw in the web managemen ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2025-15683 (TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial ...)
 	TODO: check
 CVE-2025-15682 (TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exh ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86ba8288e309bbba1885e4a8bb2347732f4809c2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86ba8288e309bbba1885e4a8bb2347732f4809c2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/ed5c7d6b/attachment.htm>


More information about the debian-security-tracker-commits mailing list