[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Sep 6 08:14:04 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bde5f90c by security tracker role at 2026-09-06T07:13:57+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9,71 +9,71 @@ CVE-2026-86171 (A security vulnerability has been detected in DefaultFuction CRM
 CVE-2026-86170 (A weakness has been identified in DefaultFuction CRM 1.0.0. The impact ...)
 	TODO: check
 CVE-2026-86168 (A security flaw has been discovered in code-projects Content Managemen ...)
-	TODO: check
+	NOT-FOR-US: code-projects
 CVE-2026-86167 (A vulnerability was identified in Tenda HG10 300001138. Impacted is th ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-86166 (A vulnerability was determined in Tenda HG10 300001138. This issue aff ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-86165 (A vulnerability was found in Tenda HG10 300001138. This vulnerability  ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-86164 (A security flaw has been discovered in itsourcecode Sales and Inventor ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-86163 (A vulnerability was identified in itsourcecode Sales and Inventory Sys ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-86162 (A vulnerability was determined in SourceCodester Online Voting System  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-86161 (A vulnerability was found in SourceCodester Online Voting System 1.0.  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-86160 (A vulnerability has been found in SourceCodester Online Voting System  ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-86159 (A flaw has been found in SourceCodester Online Voting System 1.0. Impa ...)
-	TODO: check
+	NOT-FOR-US: SourceCodester
 CVE-2026-86153 (A vulnerability has been found in Tenda CP3 27.5.57.101. This affects  ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-86152 (A flaw has been found in Tenda CP3 27.5.57.101. The impacted element i ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-86151 (A vulnerability was detected in Tenda CP3 27.5.57.101. The affected el ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-86150 (A security vulnerability has been detected in Tenda CP3 27.5.57.101. I ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-86149 (A weakness has been identified in Tenda CP3 27.5.57.101. This issue af ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-86148 (A security flaw has been discovered in Tenda CP3 27.5.57.101. This vul ...)
-	TODO: check
+	NOT-FOR-US: Tenda
 CVE-2026-86060 (RouterOS contains an argument-handling flaw in the SSH login path invo ...)
 	TODO: check
 CVE-2026-85038 (The B2BKing \u2014 Ultimate WooCommerce B2B and Wholesale Plugin \u201 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84219 (The Kirki  WordPress plugin before 6.3.0 does not hold back every spel ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84028 (The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-76161
 	REJECTED
 CVE-2026-76160
 	REJECTED
 CVE-2026-75816 (The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-75793 (The SureCart  WordPress plugin before 4.7.0 does not consult the site' ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-67281 (RouterOS WebFig contains an unauthenticated file-read vulnerability in ...)
 	TODO: check
 CVE-2026-67279 (RouterOS SSH enters the connection protocol after a client-requested r ...)
 	TODO: check
 CVE-2026-67278 (MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during  ...)
-	TODO: check
+	NOT-FOR-US: MikroTik
 CVE-2026-67277 (RouterOS accepts a "related" btest connection before the corresponding ...)
 	TODO: check
 CVE-2026-67276 (RouterOS does not compare the complete RSA public key when matching an ...)
 	TODO: check
 CVE-2026-18480 (The SureCart  WordPress plugin before 4.6.3 does not ensure that the a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18056 (The HivePress Authentication plugin for WordPress is vulnerable to Aut ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16310 (The MemberDash plugin for WordPress is vulnerable to Insecure Direct O ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13159 (The Real Estate Papi WordPress theme through 1.0.5 does not perform ca ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-85498 [Regression in CVE-2026-4897 fix (polkit read_cookie()) - stack buffer underflow]
 	- policykit-1 <unfixed>
 	[trixie] - policykit-1 <not-affected> (Fix for CVE-2026-4897 not applied)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bde5f90c0776945be0d005b8651350b656eb60ab

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bde5f90c0776945be0d005b8651350b656eb60ab
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/b43d207d/attachment.htm>


More information about the debian-security-tracker-commits mailing list