[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 20 08:41:46 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a0e498b2 by security tracker role at 2026-08-20T07:14:29+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-8619 (An unauthenticated denial-of-service vulnerability was identified in T ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2026-76957 (libexpat before 2.8.4 lacks handler call depth tracking with custom en ...)
 	TODO: check
 CVE-2026-76956 (In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentr ...)
@@ -65,7 +65,7 @@ CVE-2026-76827 (A flaw was found in search-indexer. This vulnerability allows a
 CVE-2026-76800 (A flaw has been found in DeDeCMS 3. Affected by this vulnerability is  ...)
 	TODO: check
 CVE-2026-76799 (A weakness has been identified in code-projects Login Registration Sys ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-76795 (A vulnerability has been found in AeternaLabsHQ PullMD 3.2.0. This imp ...)
 	TODO: check
 CVE-2026-76785 (A security flaw has been discovered in amirsanni Mini-Inventory-and-Sa ...)
@@ -73,7 +73,7 @@ CVE-2026-76785 (A security flaw has been discovered in amirsanni Mini-Inventory-
 CVE-2026-76783 (A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This  ...)
 	TODO: check
 CVE-2026-76764 (A flaw has been found in code-projects Employee Management System 1.0. ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-76762 (A vulnerability was detected in code-projects Assessment Management 1. ...)
 	TODO: check
 CVE-2026-76761 (A vulnerability was identified in chenhg5 cc-connect up to 1.4.1. This ...)
@@ -83,253 +83,253 @@ CVE-2026-76760 (A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Aff
 CVE-2026-76647 (Leantime JSON-RPC API through version 3.9.0 contains a missing authori ...)
 	TODO: check
 CVE-2026-76591 (A security flaw has been discovered in TRENDnet TEW-755AP up to 202607 ...)
-	TODO: check
+	NOT-FOR-US: TRENDnet
 CVE-2026-76590 (A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. A ...)
-	TODO: check
+	NOT-FOR-US: TRENDnet
 CVE-2026-76589 (A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affect ...)
-	TODO: check
+	NOT-FOR-US: TRENDnet
 CVE-2026-76584 (A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03.  ...)
-	TODO: check
+	NOT-FOR-US: TRENDnet
 CVE-2026-76583 (A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affec ...)
-	TODO: check
+	NOT-FOR-US: TRENDnet
 CVE-2026-76582 (A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affec ...)
-	TODO: check
+	NOT-FOR-US: TRENDnet
 CVE-2026-76576 (A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. This ...)
 	TODO: check
 CVE-2026-76574 (A flaw has been found in code-projects Hospital Information System 1.0 ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-76572 (A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3. ...)
 	TODO: check
 CVE-2026-76405 (In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76404 (In Splunk MCP Server app versions below 1.2.1, a user who holds the "a ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76403 (In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated u ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76402 (In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated u ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76401 (In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated u ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76400 (In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated u ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76399 (In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76398 (In Splunk AI Toolkit versions below 6.0.1, a user who does not hold th ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76397 (In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76396 (In Splunk AI Toolkit versions below 6.0.0, a user that holds a role wi ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76395 (In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76394 (In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who d ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76393 (In Splunk AI Toolkit versions below 6.0.0, a user who can upload model ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76392 (In Splunk AI Toolkit versions below 6.0.0, a user who does not hold th ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76391 (In Splunk AI Toolkit versions below 6.0.0, a user who does not hold th ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76390 (In Cisco Talos Intelligence for Enterprise Security Cloud versions bel ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76389 (In Cisco Talos Intelligence for Enterprise Security Cloud versions bel ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76388 (In Splunk Enterprise Security versions below 8.6.1, a user who holds t ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76387 (In Splunk Enterprise Security versions below 8.6.1, a user who holds a ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76386 (In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who ho ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76385 (In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who  ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76384 (In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Sp ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76383 (In versions below 1.0.5 of the RSA SecurID Authentication Manager app  ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76382 (In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76381 (In versions below 1.5.2 of the MS Graph for Active Directory app for S ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76380 (In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SO ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76379 (In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76378 (In versions below 2.4.5 of the Cisco Secure Malware Analytics app for  ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76377 (In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a u ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76376 (In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76375 (In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76374 (In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76373 (In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76372 (In Nmap Scanner versions below 3.0.15, a user who holds a role that ca ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76371 (In FireAMP versions below 2.1.15, a user who holds a role that can edi ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76370 (In Splunk SOAR versions below 8.6.0, an authenticated user with restri ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76369 (In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broke ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76368 (In Splunk SOAR versions below 8.6.0, a user who holds a role that cont ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76367 (In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Co ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76366 (In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR a ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76365 (In Splunk SOAR versions below 8.6.0, a user who holds the "Automation  ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76364 (In Splunk SOAR versions below 8.6.0, a user who holds the "Automation  ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76363 (In Splunk SOAR versions below 8.6.0, a user who holds the "Automation  ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76362 (In Splunk SOAR versions below 8.6.0, an unauthenticated user who can o ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76361 (In Splunk SOAR versions below 8.6.0, a user with the "Administrator" r ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76360 (In Splunk SOAR versions below 8.6.0, an authenticated user with no rol ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76359 (In Splunk SOAR versions below 8.6.0, a user who holds the Administrato ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76358 (In Splunk SOAR versions below 8.6.0, a user with app-install privilege ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76357 (In Splunk SOAR versions below 8.6.0, an authenticated user with no rol ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76356 (In Splunk SOAR versions below 8.6.0, an unauthenticated user could spo ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76355 (In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated us ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76354 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76353 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76352 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76351 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76350 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76349 (In Splunk Enterprise versions below 10.2.6, 10.0.9, and 9.4.14, an una ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76348 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76347 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76346 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76345 (In Splunk Enterprise versions below 10.4.2, a user with a high-privile ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76344 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76343 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76342 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76341 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76340 (In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated us ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76339 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76338 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76337 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76336 (In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76335 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76334 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76333 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76332 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76331 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76330 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76329 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76328 (In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76327 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76326 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76325 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76324 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76323 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76322 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76321 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76320 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76319 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76318 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76317 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76316 (In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76315 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76314 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76313 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76312 (In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76311 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76310 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76309 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76263 (In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76262 (In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated us ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76261 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76260 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76259 (In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76258 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76257 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76256 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76255 (In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.8, and 9.4.13 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76254 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, an ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76253 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76252 (In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.13 ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76251 (In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76139 (A flaw was found in acm-operator-bundle. The build process for this co ...)
 	TODO: check
 CVE-2026-75963 (The Events Made Easy plugin for WordPress is vulnerable to Local File  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-75860 (The JSON Options WordPress plugin through 0.0.4 does not have any capa ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-75628 (Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen of ...)
 	TODO: check
 CVE-2026-75616 (An OS command injection vulnerability exists in the web management int ...)
-	TODO: check
+	NOT-FOR-US: TPLink
 CVE-2026-75596 (Netty is an asynchronous, event-driven network application framework.  ...)
 	TODO: check
 CVE-2026-75595 (Netty is an asynchronous, event-driven network application framework.  ...)
@@ -339,11 +339,11 @@ CVE-2026-75593 (BuildKit is a toolkit for converting source code to build artifa
 CVE-2026-75569 (A flaw was found in mce-operator-bundle. The build process fetches and ...)
 	TODO: check
 CVE-2026-75476 (Tanium addressed a compression bomb vulnerability in Threat Response.)
-	TODO: check
+	NOT-FOR-US: Tanium
 CVE-2026-75112 (A security issue exists within OTTO\xae Fleet Manager. The vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2026-74992 (The Kirki  WordPress plugin before 6.2.3 does not properly validate th ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-74228
 	REJECTED
 CVE-2026-74227
@@ -355,7 +355,7 @@ CVE-2026-73542 (Multiple SEIKO EPSON printers and scanners contain revoked root
 CVE-2026-71368 (F-RevoCRM contains a cross-site scripting vulnerability. If a user vie ...)
 	TODO: check
 CVE-2026-69550 (Out-of-bounds read in Remote Desktop Client allows an unauthorized att ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-69222 (LiquidJS is a Shopify / GitHub Pages compatible template engine in pur ...)
 	TODO: check
 CVE-2026-68901 (Wekan is open source kanban built with Meteor. Prior to 10.38, the /ap ...)
@@ -391,7 +391,7 @@ CVE-2026-63187 (Logto is the modern, open-source auth infrastructure for SaaS an
 CVE-2026-63123 (Tina is a headless content management system. Prior to 2.5.2, the Tina ...)
 	TODO: check
 CVE-2026-62727 (Concurrent execution using shared resource with improper synchronizati ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-62317 (Logto is the modern, open-source auth infrastructure for SaaS and AI a ...)
 	TODO: check
 CVE-2026-61712 (BuildKit is a toolkit for converting source code to build artifacts in ...)
@@ -447,17 +447,17 @@ CVE-2026-53545 (Termix is a web-based server management platform with SSH termin
 CVE-2026-53542 (Termix is a web-based server management platform with SSH terminal, tu ...)
 	TODO: check
 CVE-2026-4937 (IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-4936 (IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110. ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-22306 (Download of code without integrity check, inclusion of functionality f ...)
 	TODO: check
 CVE-2026-19699 (The GutenKit  WordPress plugin before 2.5.0 does not have a sufficient ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19697 (The GutenKit  WordPress plugin before 2.5.0 does not sanitise uploaded ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19615 (The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 do ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19582 (In binutils 2.46.1 and prior versions, a victim who opens a crafted PE ...)
 	TODO: check
 CVE-2026-19563
@@ -477,175 +477,175 @@ CVE-2026-19506 (Race condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkst
 CVE-2026-19505 (Improper cryptographic signature verification in `jst_functions.c` in  ...)
 	TODO: check
 CVE-2026-18871 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18862
 	REJECTED
 CVE-2026-18849 (IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18821 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060. ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18544 (IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18502
 	REJECTED
 CVE-2026-18102 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17590
 	REJECTED
 CVE-2026-17414 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060. ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17153 (The AI Agent by SiteGround plugin for WordPress is vulnerable to autho ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-17097 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060. ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17091 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060. ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17063 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17042 (IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.00 through ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17028 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060. ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-17015 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16933 (IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1 ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16919 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16917 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16914 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16913 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16911 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16909 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16903 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16901 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16897 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16894 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16891 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16890 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16888 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16886 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16885 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16883 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16882 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16877 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16875 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16874 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16873 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16872 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16869 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16866 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16865 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16864 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16862 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16857 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16855 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16852 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16851 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16850 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16849 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16848 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16847 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16846 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16845 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16844 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16842 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16841 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16840 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16839 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16838 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local atta ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16837 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16836 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16834 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16833 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16831 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16829 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16827 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16825 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote aut ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16824 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16822 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote att ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16724 (IBM Virtualization Management Interface FW1110.00 through FW1110.30, F ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16707 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060. ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-16661 (IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060. ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-15049 (The Depicter \u2014 Popup & Slider Builder WordPress plugin before 4.8 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-14978 (HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-14514 (IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remo ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-14163 (In affected versions of Octopus Server under certain circumstances it  ...)
-	TODO: check
+	NOT-FOR-US: Octopus Deploy
 CVE-2026-13405 (The Royal Addons for Elementor  WordPress plugin before 1.7.1066 does  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12634 (The NVS backend of the Zephyr settings subsystem (subsys/settings/src/ ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12633 (The IPv6 neighbor-discovery code in subsys/net/ip/ipv6_nbr.c processes ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-12522 (The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd ...)
-	TODO: check
+	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11617 (Tanium addressed a compression bomb vulnerability in Findings.)
-	TODO: check
+	NOT-FOR-US: Tanium
 CVE-2025-36398 (IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-36255 (IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-36254 (IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F  ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2025-14602 (The application generates uploaded file names using a weak and predict ...)
 	TODO: check
 CVE-2022-4996 (A flaw has been found in mruby 3.1.0. Affected is the function udiv of ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a0e498b270a9d5a784f65e38f85a1aea95c5c7c3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a0e498b270a9d5a784f65e38f85a1aea95c5c7c3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/76c44b49/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list