[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 1 20:14:05 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f10c6113 by security tracker role at 2026-09-01T19:13:57+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,17 +1,17 @@
 CVE-2026-9637 (A denial-of-service security issue exists in the affected Logix platfo ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2026-9634 (A security issue exists within the Redundancy Module Configuration Too ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2026-9633 (A security issue exists within the Redundancy Module Configuration Too ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2026-9625 (A denial-of-service security issue exists within RSLinx\xae Classic. A ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2026-9624 (A denial-of-service security issue exists within RSLinx\xae Classic. A ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2026-9622 (A denial-of-service security issue exists within RSLinx\xae Classic. A ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2026-9621 (A denial-of-service security issue exists within RSLinx\xae Classic. T ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2026-8712 (Wyoming before 1.10.2 contains a server-side request forgery vulnerabi ...)
 	TODO: check
 CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
@@ -29,7 +29,7 @@ CVE-2026-84268 (A flaw was found in the SFTP backend in gvfs. When mounting a sh
 CVE-2026-84267 (A flaw was found in the SFTP backend in gvfs. When mounting a share, a ...)
 	TODO: check
 CVE-2026-84235 (A denial-of-service security issue exists in the affected product. The ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2026-84233 (A flaw was found in rpm. A local attacker could supply a specially cra ...)
 	TODO: check
 CVE-2026-84232 (A flaw was found in pulpcore's content serving application. Files uplo ...)
@@ -133,7 +133,7 @@ CVE-2026-83595 (AVideo contains a cross-site request forgery vulnerability in pl
 CVE-2026-83557 (DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator appli ...)
 	TODO: check
 CVE-2026-83551 (Cleartext storage of sensitive information in the @step and @remote de ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-82927 (Untrusted pointer dereference vulnerability in Samsung Open Source mTo ...)
 	TODO: check
 CVE-2026-82926 (NULL pointer dereference vulnerability in Samsung Open Source mTower a ...)
@@ -141,33 +141,33 @@ CVE-2026-82926 (NULL pointer dereference vulnerability in Samsung Open Source mT
 CVE-2026-80047 (A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and < ...)
 	TODO: check
 CVE-2026-7877 (The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-79687 (Dell PowerStore SDNAS contains a Missing Authentication for Critical F ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-79686 (Dell PowerStore contains a Protection Mechanism Failure vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-79685 (Dell PowerStore contains an Argument Injection vulnerability. An authe ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-79684 (Dell PowerStore contains a Protection Mechanism Failure vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-79683 (Dell PowerStore contains a Protection Mechanism Failure vulnerability. ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-79682 (Dell PowerStore contains a Command Injection vulnerability. An authent ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-78363 (The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcod ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-78012 (An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow  ...)
 	TODO: check
 CVE-2026-77194 (The Simple Membership plugin for WordPress is vulnerable to Authentica ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-76111 (Dell PowerStore contains an Incorrect Authorization vulnerability. An  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-75538 (An attacker that connects to an open Erlang TCP port that uses the ine ...)
 	TODO: check
 CVE-2026-74994 (The mod_auth module in OTP's inets httpd server, when configured with  ...)
 	TODO: check
 CVE-2026-74916 (The WP Fastest Cache WordPress plugin before 1.5.1 does not include a  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-74835 (The inets application HTTP server httpd fails to enforce a configured  ...)
 	TODO: check
 CVE-2026-73812 (httpd function check_header/3 rejects duplicate Content-Length (per CV ...)
@@ -261,17 +261,17 @@ CVE-2026-59681 (A OS command injection vulnerability in yast2-auth-client allows
 CVE-2026-59680 (An OS command injection vulnerability was found in yast2-users. When d ...)
 	TODO: check
 CVE-2026-58575 (Dell PowerStore contains an Authentication Bypass by Spoofing vulnerab ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-58572 (Dell PowerStore contains a Code Injection vulnerability. An authentica ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-58571 (Dell PowerStore contains an OS Command Injection vulnerability. An aut ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-58569 (Dell PowerStore contains an Inclusion of Functionality from Untrusted  ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-58567 (Dell PowerStore contains an OS Command Injection vulnerability. An aut ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-58566 (Dell PowerStore, an Incorrect Authorization vulnerability. A low privi ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-55951 (The Erlang/OTP httpc HTTP client does not enforce a limit on the total ...)
 	TODO: check
 CVE-2026-53682 (An unauthenticated client can query the Security Domain hosts inventor ...)
@@ -295,57 +295,57 @@ CVE-2026-51974 (An eval() injection vulnerability in the get_list function in mo
 CVE-2026-51956 (A Broken Object Level Authorization vulnerability exists in Grashjs At ...)
 	TODO: check
 CVE-2026-51934 (Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-51788 (An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause ...)
 	TODO: check
 CVE-2026-51770 (Incorrect access control in the sendToMasterQosConfig function of TOTO ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51769 (Incorrect access control in the remoteCloudUpdateCheck function of TOT ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51768 (Incorrect access control in the setElinkQosConfig function of TOTOLINK ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51767 (Incorrect access control in the recvClearPairCfg function of TOTOLINK  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51766 (Incorrect access control in the setDevReboot function of TOTOLINK T6 4 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51765 (Incorrect access control in the recvIndirectMeshInfo function of TOTOL ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51764 (Incorrect access control in the recvSlaveCloudCheckStatus function of  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51763 (Incorrect access control in the freeStaClient function of TOTOLINK T6  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51762 (Incorrect access control in the meshInfoKick function of TOTOLINK T6 4 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51761 (Incorrect access control in the updateLanIp function of TOTOLINK T6 4. ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51760 (Incorrect access control in the informSyncUpgfw function of TOTOLINK T ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51757 (Incorrect access control in the meshSlaveUpdate function of TOTOLINK T ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51756 (Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51754 (Incorrect access control in the updateSlaveIpList function of TOTOLINK ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51752 (Incorrect access control in the staticInfoSend function of TOTOLINK T6 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51751 (Incorrect access control in the delSlaveDevice function of TOTOLINK T6 ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51750 (Incorrect access control in the updatePriChannel function of TOTOLINK  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51748 (Incorrect access control in the sendStaticInfoToMaster function of TOT ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51747 (Incorrect access control in the keepAlive function of TOTOLINK T6 4.1. ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51745 (Incorrect access control in the updatePriStaList function of TOTOLINK  ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51744 (Incorrect access control in the recv_mesh_info_sync function of TOTOLI ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51743 (Incorrect access control in the guest_wifi_sync function of TOTOLINK T ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51742 (Incorrect access control in the discoverWan function of TOTOLINK T6 4. ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-51741 (Incorrect access control in the clearDiagnosisLog function of TOTOLINK ...)
-	TODO: check
+	NOT-FOR-US: TOTOLINK
 CVE-2026-4813 (A vulnerability in the Lutece Core XSL export management module up to  ...)
 	TODO: check
 CVE-2026-49329 (A flaw was found in openshift/oauth-server. The OAuth login and error  ...)
@@ -353,7 +353,7 @@ CVE-2026-49329 (A flaw was found in openshift/oauth-server. The OAuth login and
 CVE-2026-25706 (Improper neutralization of special elements used in an OS command in y ...)
 	TODO: check
 CVE-2026-19914 (The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cr ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19593 (OpenAI Codex Desktop for Windows and macOS automatically inspected Git ...)
 	TODO: check
 CVE-2026-19592 (OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for W ...)
@@ -363,11 +363,11 @@ CVE-2026-19591 (OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop
 CVE-2026-19590 (OpenAI Codex Desktop for Windows and macOS could execute attacker-cont ...)
 	TODO: check
 CVE-2026-19513 (The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19472 (A denial-of-service security issue exists within ArmorStart\xae LT. Th ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2026-19471 (Multiple stored cross-site scripting security issues exist within Armo ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2026-18931 (Use of Hard-coded Credentials vulnerability in TMT Machine Industry an ...)
 	TODO: check
 CVE-2026-18808 (Improper Control of Generation of Code ('Code Injection') vulnerabilit ...)
@@ -381,47 +381,47 @@ CVE-2026-18765 (Improper neutralization of special elements used in an SQL comma
 CVE-2026-18630 (Improper neutralization of special elements used in an SQL command ('S ...)
 	TODO: check
 CVE-2026-18550 (The Nokri - Job Board WordPress Theme for WordPress is vulnerable to P ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18210 (Improper neutralization of special elements used in an SQL command ('S ...)
 	TODO: check
 CVE-2026-16788 (The Live Composer \u2013 Free WordPress Website Builder plugin for Wor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16786 (The Live Composer \u2013 Free WordPress Website Builder plugin for Wor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16675 (A privilege escalation security issue exists within FactoryTalk\xae Ac ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2026-15101 (The WPBakery Page Builder plugin for WordPress is vulnerable to Stored ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13611 (The KiviCare WordPress plugin before 4.5.5 does not perform authorizat ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13348 (CWE-307: Improper Restriction of Excessive Authentication Attempts vul ...)
-	TODO: check
+	NOT-FOR-US: Schneider Electric
 CVE-2026-13337 (CWE-564: SQL Injection: Hibernate vulnerability exists that could allo ...)
-	TODO: check
+	NOT-FOR-US: Schneider Electric
 CVE-2026-13336 (CWE-78: Improper Neutralization of Special Elements used in an OS Comm ...)
-	TODO: check
+	NOT-FOR-US: Schneider Electric
 CVE-2026-12663 (A security issue exists within ControlFLASH\u2122, where the installer ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2026-12661 (A denial-of-service security issue exists within FactoryTalk\xae Histo ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2026-11873 (An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/res ...)
 	TODO: check
 CVE-2026-10420 (Untrusted pointer dereference vulnerability in Samsung Open Source mTo ...)
 	TODO: check
 CVE-2026-10195 (The FS-Poster plugin for WordPress is vulnerable to Remote Code Execut ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-15613 (Kyverno before v1.13.4 is vulnerable to server-side request forgery (S ...)
 	TODO: check
 CVE-2025-12768 (A security issue exists within FactoryTalk\xae Historian Machine Editi ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2024-7953 (A vulnerability exists in the affected products that allows a threat a ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2024-7952 (A data exposure vulnerability exists in the affected product. There ar ...)
-	TODO: check
+	NOT-FOR-US: Rockwell Automation
 CVE-2024-14047 (A local vulnerability in the Winlogbeat Windows installer caused runti ...)
 	TODO: check
 CVE-2024-10085 (CWE-770: Allocation of Resources Without Limits or Throttlingvulnerabi ...)
-	TODO: check
+	NOT-FOR-US: Schneider Electric
 CVE-2023-54356 (Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites ...)
 	TODO: check
 CVE-2026-84145 (Internally found bugs present in Firefox 154, Firefox ESR 153.1, Firef ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f10c61131097e4e9b5cdd91e970c54ae1f5751ec

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f10c61131097e4e9b5cdd91e970c54ae1f5751ec
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/000c6ee6/attachment.htm>


More information about the debian-security-tracker-commits mailing list