[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 8 08:13:55 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d98413f5 by security tracker role at 2026-09-08T07:13:48+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -17,7 +17,7 @@ CVE-2026-86519 (A vulnerability was found in code-projects Student Crud Operatio
 CVE-2026-86518 (A vulnerability has been found in code-projects Student Crud Operation ...)
 	TODO: check
 CVE-2026-86517 (A flaw has been found in itsourcecode Sales and Inventory System 1.0.  ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-86516 (A vulnerability was detected in elenavanengelenmaslova mocknest-server ...)
 	TODO: check
 CVE-2026-86515 (A security vulnerability has been detected in vgmstream up to r2117. I ...)
@@ -31,9 +31,9 @@ CVE-2026-86512 (A vulnerability was identified in java-json-tools json-patch up
 CVE-2026-86511 (A vulnerability was found in java-json-tools jackson-coreutils 2.0. Af ...)
 	TODO: check
 CVE-2026-86510 (A vulnerability has been found in D-Link DIR-822A A_101. Affected is t ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-86509 (A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the f ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-86439 (knowns versions before 0.30.0 fail to validate filesystem paths in MCP ...)
 	TODO: check
 CVE-2026-86438 (Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBr ...)
@@ -63,63 +63,63 @@ CVE-2026-82584 (Improper Neutralization of Escape, Meta, or Control Sequences vu
 CVE-2026-81638 (Improper Handling of Alternate Encoding vulnerability in ash-project a ...)
 	TODO: check
 CVE-2026-76977 (SAP UI5 does not sufficiently validate the parent frame's origin again ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-76971 (Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manuf ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-76969 (@sap/cds-mtxs NPM library does not perform sufficient checks on certai ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-76968 (SAP Web Dispatcher, Internet Communication Manager and SAP Content Ser ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-76967 (SAP NetWeaver Business Client does not perform sufficient validation w ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-76963 (Due to a missing authorization check in Application Server ABAP of SAP ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-76962 (SAP S/4HANA (Manage Bank Chains app) does not perform sufficient autho ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-76961 (SAP S/4HANA Finance (Advanced Payment Management) does not perform suf ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-76960 (SAP S/4HANA Finance (Advanced Payment Management) does not perform suf ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-76959 (SAP S/4HANA Finance (Advanced Payment Management) does not perform suf ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-76958 (SAP Integration Suite does not sufficiently validate XML documents acc ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-75811 (Improper Restriction of Software Interfaces to Hardware Features in AS ...)
-	TODO: check
+	NOT-FOR-US: ASUS
 CVE-2026-75810 (Exposed Dangerous Method or Function in ASUSArmoury Crate allow a loca ...)
-	TODO: check
+	NOT-FOR-US: ASUS
 CVE-2026-75809 (Exposed IOCTL with insufficient access control in ASUSArmoury Crate al ...)
-	TODO: check
+	NOT-FOR-US: ASUS
 CVE-2026-75808 (Allocation of Resources Without Limits or Throttling in ASUSArmoury Cr ...)
-	TODO: check
+	NOT-FOR-US: ASUS
 CVE-2026-75650 (Adobe Commerce is affected by an Improper Neutralization of Special El ...)
-	TODO: check
+	NOT-FOR-US: Adobe
 CVE-2026-66768 (SAP GUI for Java does not correctly enforce the trust level policy for ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-66767 (SAP NetWeaver Application Server for ABAP and ABAP Platform allows an  ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-58240 (SAP NetWeaver Message Server does not sufficiently validate the authen ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-58234 (SAP Process Integration (SOAP Adapter) allows a privileged user to sen ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-44766 (SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-pr ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-44756 (A memory safety vulnerability exists in the Extended Passport Protocol ...)
-	TODO: check
+	NOT-FOR-US: SAP
 CVE-2026-19397 (Missing authentication for a critical function in ASUS Control Center  ...)
-	TODO: check
+	NOT-FOR-US: ASUS
 CVE-2026-18023 (Sensitive Information in Resource Not Removed Before Reuse in ASUS Arm ...)
-	TODO: check
+	NOT-FOR-US: ASUS
 CVE-2026-16006 (Exposure of Sensitive System Information to an Unauthorized Control Sp ...)
-	TODO: check
+	NOT-FOR-US: ASUS
 CVE-2026-16005 (Release of Invalid Pointer or Reference in Armoury Crate driver allows ...)
-	TODO: check
+	NOT-FOR-US: ASUS
 CVE-2026-16004 (Exposed IOCTL with Insufficient Access Control in Armoury Crate driver ...)
-	TODO: check
+	NOT-FOR-US: ASUS
 CVE-2026-16003 (Exposed IOCTL with Insufficient Access Control in Armoury Crate driver ...)
-	TODO: check
+	NOT-FOR-US: ASUS
 CVE-2026-12962 (A Permissive Cross-domain Security Policy with Untrusted Domains in Ar ...)
-	TODO: check
+	NOT-FOR-US: ASUS
 CVE-2026-8279 (The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized d ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-86506 (In JetBrains GoLand before 2026.2.2.1 missing authentication on the Go ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d98413f5798200b46b4397e6f5421c278576b659

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d98413f5798200b46b4397e6f5421c278576b659
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260908/b0a309df/attachment.htm>


More information about the debian-security-tracker-commits mailing list