[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 9 16:24:44 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c717408a by Moritz Muehlenhoff at 2026-09-09T17:24:24+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -708,7 +708,7 @@ CVE-2026-81975 (Acrobat Reader is affected by a Use After Free vulnerability tha
 CVE-2026-81973 (Acrobat Reader is affected by a Use After Free vulnerability that coul ...)
 	NOT-FOR-US: Adobe
 CVE-2026-81904 (Concrete CMS below 9.5.3 registered view assets for every sub-block of ...)
-	TODO: check
+	NOT-FOR-US: Concrete CMS
 CVE-2026-81741 (The Groundhogg \u2014 CRM, Newsletters, and Marketing Automation WordP ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-81647 (Out-of-bounds read vulnerability in the graphics module. Impact: Succe ...)
@@ -718,7 +718,7 @@ CVE-2026-81646 (Out-of-bounds read vulnerability in the graphics module. Impact:
 CVE-2026-81644 (DoS vulnerability in the preview service module. Impact: Successful ex ...)
 	NOT-FOR-US: Huawei
 CVE-2026-81192 (`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelem ...)
-	TODO: check
+	NOT-FOR-US: opentelemetry-dotnet-contrib
 CVE-2026-81022 (The SupportCandy  WordPress plugin before 3.5.3 does not validate a su ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-81021 (The SupportCandy  WordPress plugin before 3.5.3 does not perform an au ...)
@@ -754,17 +754,17 @@ CVE-2026-79907 (Acrobat Reader is affected by a Double Free vulnerability that c
 CVE-2026-79905 (Adobe Experience Manager is affected by a stored Cross-Site Scripting  ...)
 	NOT-FOR-US: Adobe
 CVE-2026-79588 (U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmissi ...)
-	TODO: check
+	NOT-FOR-US: U-speed WIFI4 N300
 CVE-2026-78971 (In Halo <= 2.25.4, the plugin management feature allows users to insta ...)
-	TODO: check
+	NOT-FOR-US: Halo
 CVE-2026-78834 (A code execution vulnerability exists in CMSimple 5.22 in the CoAuthor ...)
-	TODO: check
+	NOT-FOR-US: CMSimple
 CVE-2026-78742 (Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) vi ...)
-	TODO: check
+	NOT-FOR-US: Silverpeas
 CVE-2026-78741 (Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in ...)
-	TODO: check
+	NOT-FOR-US: Silverpeas
 CVE-2026-78738 (Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via  ...)
-	TODO: check
+	NOT-FOR-US: Silverpeas
 CVE-2026-78635 (The Okta Privileged Access client URL handler does not insert an optio ...)
 	NOT-FOR-US: Okta
 CVE-2026-78631 (The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to  ...)
@@ -800,7 +800,7 @@ CVE-2026-78550 (The Okta Access Gateway management console passes user-supplied
 CVE-2026-78545 (The Okta Access Gateway does not sanitize the application label field  ...)
 	NOT-FOR-US: Okta
 CVE-2026-77827 (Maono Link 3.8.13 MaonoAiServices Windows service allows local privile ...)
-	TODO: check
+	NOT-FOR-US: MaonoAiServicesHalo
 CVE-2026-77187 (The My Calendar \u2013 Accessible Event Manager plugin for WordPress i ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77186 (The My Calendar \u2013 Accessible Event Manager plugin for WordPress i ...)
@@ -1020,25 +1020,25 @@ CVE-2026-71356 (Adobe Experience Manager is affected by a DOM-based Cross-Site S
 CVE-2026-6485 (UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell ...)
 	NOT-FOR-US: Insyde
 CVE-2026-55250 (Maravel, a PHP framework oriented towards dependency injection, prior  ...)
-	TODO: check
+	NOT-FOR-US: Maravel
 CVE-2026-53939 (OpenIDC/cjose is a C library implementing the Javascript Object Signin ...)
 	TODO: check
 CVE-2026-53938 (OpenIDC/cjose is a C library implementing the Javascript Object Signin ...)
 	TODO: check
 CVE-2026-53937 (MCP Kotlin SDK is the Kotlin Multiplatform software development kit fo ...)
-	TODO: check
+	NOT-FOR-US: MCP Kotlin SDK
 CVE-2026-53933 (Maravel, a PHP framework oriented towards dependency injection, prior  ...)
-	TODO: check
+	NOT-FOR-US: Maravel
 CVE-2026-53639 (Sylius is an Open Source eCommerce Framework on Symfony. Starting in v ...)
-	TODO: check
+	NOT-FOR-US: Sylius
 CVE-2026-53638 (Sylius is an Open Source eCommerce Framework on Symfony. Starting in v ...)
-	TODO: check
+	NOT-FOR-US: Sylius
 CVE-2026-53637 (Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0. ...)
-	TODO: check
+	NOT-FOR-US: Sylius
 CVE-2026-53581 (OPNsense is a FreeBSD based firewall and routing platform. Prior to ve ...)
-	TODO: check
+	NOT-FOR-US: OPNsense
 CVE-2026-52486 (An issue in OpenDDS 3.33.x allows a local attacker to cause a denial o ...)
-	TODO: check
+	NOT-FOR-US: OpenDDS
 CVE-2026-49883 (In checkReadPermission of PermissionsManager.java, there is a possible ...)
 	NOT-FOR-US: Android
 CVE-2026-49315 (DoS vulnerability in the input device module. Impact: Successful explo ...)
@@ -1066,7 +1066,7 @@ CVE-2026-49153
 CVE-2026-48273 (ColdFusion is affected by an Improper Neutralization of Directives in  ...)
 	NOT-FOR-US: Adobe
 CVE-2026-47680 (The source-controller is a Kubernetes operator, specialised in artifac ...)
-	TODO: check
+	NOT-FOR-US: source-controller Kubernetes operator
 CVE-2026-45220
 	REJECTED
 CVE-2026-45219
@@ -1196,7 +1196,7 @@ CVE-2026-11821 (The Eventin \u2013 Event Calendar, Event Registration, Tickets &
 CVE-2026-11363 (The Ninja Forms \u2013 The Contact Form Builder That Grows With You pl ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-7062 (A stored cross-site scripting (XSS) vulnerability has been identified  ...)
-	TODO: check
+	NOT-FOR-US: h5p-nodejs-library
 CVE-2025-64868 (Adobe Experience Manager is affected by a stored Cross-Site Scripting  ...)
 	NOT-FOR-US: Adobe
 CVE-2025-64866 (Adobe Experience Manager is affected by a stored Cross-Site Scripting  ...)
@@ -2027,7 +2027,7 @@ CVE-2026-76191 (Animate is affected by an Improper Control of Generation of Code
 CVE-2026-75156 (Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not valida ...)
 	NOT-FOR-US: Apache Airflow provider
 CVE-2026-75021 (fastify-cli starts the Node.js Inspector when a debug flag is used, bu ...)
-	TODO: check
+	NOT-FOR-US: fastify-cli
 CVE-2026-74860 (A flaw was found in libxml2 with Python bindings enabled. A remote att ...)
 	TODO: check
 CVE-2026-74859 (The shell theme installer in gnome-tweaks extracts user-supplied ZIP a ...)
@@ -3704,15 +3704,15 @@ CVE-2026-3174 (The Event Tickets and Registration plugin for WordPress is vulner
 CVE-2026-34223 (A vulnerability has been identified in Desigo CC ClickOnce Client V6 ( ...)
 	NOT-FOR-US: Siemens
 CVE-2026-33920 (A cross-site request forgery vulnerability was discovered in the login ...)
-	TODO: check
+	NOT-FOR-US: Nozomi Networks Guardian
 CVE-2026-33391 (An access control vulnerability was discovered in the Smart Polling co ...)
-	TODO: check
+	NOT-FOR-US: Nozomi Networks Guardian
 CVE-2026-33389 (An improper certificate/host key validation vulnerability was discover ...)
-	TODO: check
+	NOT-FOR-US: Nozomi Networks Guardian
 CVE-2026-33388 (An access control vulnerability was discovered in the Credentials Mana ...)
-	TODO: check
+	NOT-FOR-US: Nozomi Networks Guardian
 CVE-2026-33387 (A template injection vulnerability was discovered in the Dashboards fu ...)
-	TODO: check
+	NOT-FOR-US: Nozomi Networks Guardian
 CVE-2026-33197 (AMI APTIOV contains a vulnerability in BIOS where a privileged user ma ...)
 	NOT-FOR-US: AMI
 CVE-2026-2520 (The Online Scheduling and Appointment Booking System \u2013 Bookly plu ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c717408ae8267a37934ac76ce02401883a0e1a14

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c717408ae8267a37934ac76ce02401883a0e1a14
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/3416a6df/attachment.htm>


More information about the debian-security-tracker-commits mailing list