[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 17 08:17:19 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ac210c50 by security tracker role at 2026-09-17T07:14:29+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,7 +1,7 @@
 CVE-2026-92839 (Canva Desktop before v1.125.0 performed double decoding in the deeplin ...)
 	TODO: check
 CVE-2026-92838 (A DLL hijacking vulnerability exists in the GeoVisionGV-Remote E-Mapde ...)
-	TODO: check
+	NOT-FOR-US: GeoVision
 CVE-2026-92816 (ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset s ...)
 	TODO: check
 CVE-2026-92815 (changedetection.io through 0.60.6 fails to validate the Goto URL actio ...)
@@ -19,7 +19,7 @@ CVE-2026-92810 (PrestaShop blockwishlist through 3.0.2 fails to validate wishlis
 CVE-2026-92809 (PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR co ...)
 	TODO: check
 CVE-2026-92808 (A server-side request forgery (SSRF) vulnerability exists in the Unifi ...)
-	TODO: check
+	NOT-FOR-US: Altium
 CVE-2026-92806 (phpList versions before 3.6.17 fail to validate cross-site request for ...)
 	TODO: check
 CVE-2026-92805 (UVdesk Community Skeleton through 1.1.8 fails to authenticate or valid ...)
@@ -125,21 +125,21 @@ CVE-2026-92596 (Nodemailer before 9.1.0 contains a quadratic time complexity vul
 CVE-2026-92595 (Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do no ...)
 	TODO: check
 CVE-2026-92594 (Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authori ...)
-	TODO: check
+	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-92593 (Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix fo ...)
-	TODO: check
+	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-92592 (Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authe ...)
-	TODO: check
+	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-92591 (Craft CMS 5.0.0 through 5.10.12 treats a database connection failure a ...)
-	TODO: check
+	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-92590 (Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-si ...)
-	TODO: check
+	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-92589 (Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken a ...)
-	TODO: check
+	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-92588 (n8n is a workflow automation platform. In n8n versions before 1.123.76 ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-92587 (n8n is a workflow automation platform. In versions before 1.123.76, 2. ...)
-	TODO: check
+	NOT-FOR-US: n8n
 CVE-2026-92586 (AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1)  ...)
 	TODO: check
 CVE-2026-92585 (AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1)  ...)
@@ -165,7 +165,7 @@ CVE-2026-92576 (HKUDS nanobot before 0.3.0 contains a server-side request forger
 CVE-2026-92527 (A vulnerability has been found in chatwoot up to 4.17.1. This impacts  ...)
 	TODO: check
 CVE-2026-92526 (A flaw has been found in itsourcecode Leave Management System 1.0. Thi ...)
-	TODO: check
+	NOT-FOR-US: itsourcecode System
 CVE-2026-92475 (A weakness has been identified in GPAC 26.08-DEV. This impacts the fun ...)
 	TODO: check
 CVE-2026-92474 (A security flaw has been discovered in GPAC 26.08-DEV. This affects th ...)
@@ -173,93 +173,93 @@ CVE-2026-92474 (A security flaw has been discovered in GPAC 26.08-DEV. This affe
 CVE-2026-92473 (A vulnerability was identified in GPAC 26.08-DEV. The impacted element ...)
 	TODO: check
 CVE-2026-91019 (The Event Booking Manager for WooCommerce  WordPress plugin before 5.6 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-91017 (The Robokassa payment gateway for Woocommerce WordPress plugin before  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-91016 (The Motors  WordPress plugin before 1.4.121 does not verify that a req ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-91015 (The Master Addons for Elementor  WordPress plugin before 3.1.9 does no ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-91014 (The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin bef ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-91011 (The EWWW Image Optimizer WordPress plugin before 8.7.7 does not proper ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-91010 (The Invisible Anti-Spam & CAPTCHA \u2014 reCAPTCHA Alternative for All ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-91009 (The Active Woot Products Tables for WooCommerce. 100% FREE WordPress p ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-91008 (The Event Booking Manager for WooCommerce  WordPress plugin before 5.3 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-90982 (@fastify/static is a Fastify plugin that serves static files from a co ...)
 	TODO: check
 CVE-2026-90923 (The Autopay WordPress plugin before 5.0.1 does not enforce the signatu ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-90922 (The Paid Membership Subscriptions  WordPress plugin before 3.0.9 does  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-89084 (HP has identified potential security vulnerabilities in the HP Advance ...)
-	TODO: check
+	NOT-FOR-US: HP
 CVE-2026-89083 (HP has identified potential security vulnerabilities in the HP Advance ...)
-	TODO: check
+	NOT-FOR-US: HP
 CVE-2026-89082 (HP has identified potential security vulnerabilities in the HP Advance ...)
-	TODO: check
+	NOT-FOR-US: HP
 CVE-2026-89064 (The All-in-One WP Migration and Backup plugin for WordPress is vulnera ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-89034 (TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_2 ...)
 	TODO: check
 CVE-2026-88904 (The PuppyFW WordPress plugin through 0.4.4 does not have proper author ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-88795 (The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does no ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-88792 (The Dictionary WordPress plugin through 1.0 does not have authorisatio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-88592 (kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF ...)
 	TODO: check
 CVE-2026-87976 (Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipula ...)
 	TODO: check
 CVE-2026-87963 (The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or pa ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87935 (The Paid Downloads plugin for WordPress is vulnerable to Arbitrary Fil ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87836 (The Comments Import & Export WordPress plugin before 2.5.4 does not re ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87796 (The Multi Uploader for Gravity Forms plugin for WordPress is vulnerabl ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87786 (The Dewa Kirim  WordPress plugin through 1.0.0 does not escape deliver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87116 (Tanium addressed a server-side request forgery vulnerability in Threat ...)
-	TODO: check
+	NOT-FOR-US: Tanium
 CVE-2026-87113 (Tanium addressed an improper access controls vulnerability in Threat R ...)
-	TODO: check
+	NOT-FOR-US: Tanium
 CVE-2026-87105 (Tanium addressed a SQL injection vulnerability in Threat Response.)
-	TODO: check
+	NOT-FOR-US: Tanium
 CVE-2026-87076 (Tanium addressed an information disclosure vulnerability in Discover.)
-	TODO: check
+	NOT-FOR-US: Tanium
 CVE-2026-87026 (Tanium addressed an improper access controls vulnerability in Threat R ...)
-	TODO: check
+	NOT-FOR-US: Tanium
 CVE-2026-87024 (Tanium addressed a SQL injection vulnerability in Asset.)
-	TODO: check
+	NOT-FOR-US: Tanium
 CVE-2026-86865 (Tanium addressed a SQL injection vulnerability in Asset.)
-	TODO: check
+	NOT-FOR-US: Tanium
 CVE-2026-86831 (Improper validation of pod identifier uniqueness in aws-network-policy ...)
-	TODO: check
+	NOT-FOR-US: Amazon
 CVE-2026-86824 (The Newsletter  WordPress plugin before 9.3.8 does not generate its em ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86801 (The To Do List Member WordPress plugin from 1.4 through 1.6 ships a fi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86788 (The HT Mega Addons for Elementor  WordPress plugin before 3.2.6 does n ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86710 (The Login with QR WordPress plugin through 1.0.0 does not verify that  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86709 (The Pressengine WordPress plugin through 1.0 does not stop its login h ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86707 (The Private Feed Key WordPress plugin through 0.1 does not verify that ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86446 (The LearnPress  WordPress plugin before 4.4.7 does not restrict the co ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86311 (The Photo Gallery by 10Web \u2013 Mobile-Friendly Image Gallery plugin ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86089 (Apache NiFi 2.11.0 supports migrating the contents of a version-contro ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-86071 (Junrar is an open source Java RAR archive library. Prior to version 7. ...)
 	TODO: check
 CVE-2026-85789
@@ -267,11 +267,11 @@ CVE-2026-85789
 CVE-2026-85469 (A flaw was found in quay-builder-qemu. A remote attacker could exploit ...)
 	TODO: check
 CVE-2026-85130 (The WPLP Cookie Consent  WordPress plugin before 4.4.4 does not escape ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-85128 (The Choose User Role at Registration WordPress plugin before 1.3.3 doe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82561 (Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-81872 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to v ...)
 	TODO: check
 CVE-2026-81871 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to v ...)
@@ -281,7 +281,7 @@ CVE-2026-81870 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. From
 CVE-2026-81869 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. From versi ...)
 	TODO: check
 CVE-2026-81866 (Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration updat ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-81546 (The Affinity by Canva application before 3.3.0 (September 2026 release ...)
 	TODO: check
 CVE-2026-76646 (A remote attacker could cause excessive resource consumption by supply ...)
@@ -305,7 +305,7 @@ CVE-2026-76444 (A vulnerability in an internal service of Cisco ISE and Cisco IS
 CVE-2026-76439 (A vulnerability in the endpoint posture status reporting functionality ...)
 	TODO: check
 CVE-2026-76438 (A vulnerability in the web-based management interface of Cisco BroadWo ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76434 (A vulnerability in the certificate import functionality of the web-bas ...)
 	TODO: check
 CVE-2026-76433 (A vulnerability in the client provisioning download feature of Cisco I ...)
@@ -321,9 +321,9 @@ CVE-2026-76427 (A vulnerability in the offline profiler feed service of Cisco IS
 CVE-2026-76426 (A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could a ...)
 	TODO: check
 CVE-2026-76425 (A vulnerability in the APIs of Cisco ISE could allow an authenticated, ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76424 (A vulnerability in the REST API of Cisco ISE could allow an authentica ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-76423 (A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could a ...)
 	TODO: check
 CVE-2026-76413 (A vulnerability in Cisco Adaptive Security Device Manager (ASDM) singl ...)
@@ -331,15 +331,15 @@ CVE-2026-76413 (A vulnerability in Cisco Adaptive Security Device Manager (ASDM)
 CVE-2026-76412 (A vulnerability in the remote diagnostics debugger of Cisco Secure FMC ...)
 	TODO: check
 CVE-2026-76409 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-75513 (Marten is a .NET Transactional Document DB and Event Store on PostgreS ...)
 	TODO: check
 CVE-2026-73462 (On affected platforms running Arista EOS with IGMP (Internet Group Man ...)
-	TODO: check
+	NOT-FOR-US: Arista Networks
 CVE-2026-70469 (Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-65388 (A remote attacker who controls a container registry may be able to dir ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-64684 (RMCP is an official Rust SDK for the Model Context Protocol. Prior to  ...)
 	TODO: check
 CVE-2026-63506 (Tina is a headless content management system. Prior to @tinacms/auth 1 ...)
@@ -369,45 +369,45 @@ CVE-2026-61589 (djust provides Phoenix LiveView-style reactive server-side rende
 CVE-2026-61588 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
 	TODO: check
 CVE-2026-50604 (A vulnerability has been identified in the Acer Agent Service componen ...)
-	TODO: check
+	NOT-FOR-US: Acer
 CVE-2026-50603 (A vulnerability has been identified in the Acer Agent Service componen ...)
-	TODO: check
+	NOT-FOR-US: Acer
 CVE-2026-44940 (The rancher-extension-stackstate extension in SUSE Observability expos ...)
 	TODO: check
 CVE-2026-25294 (Transient DOS while parsing frame during channel usage.)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-25290 (Memory Corruption when validating large data buffers from external sou ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-25284 (Information Disclosure when a pointer is reused after being deallocate ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-25283 (Memory Corruption when copying unverified data from an external source ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-25282 (Transient DOS when processing unverified data from a neighboring syste ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-25281 (Transient DOS when processing large or numerous request buffers withou ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-25280 (Memory corruption when processing escape handling flow with insufficie ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-25278 (Memory Corruption when processing I2C transfer requests due to a race  ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-25275 (Transient DOS when processing authentication frames with invalid FILS  ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-25261 (Memory corruption while processing rear sensor IOCTL calls.)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-24081 (Transient DOS when processing a channel map with insufficient used cha ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-24075 (Memory Corruption when multiple threads issue concurrent IOCTL request ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-24074 (Memory Corruption when processing data with large offset and length va ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-24073 (Memory corruption when processing decode statistics due to insufficien ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2026-20361 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20360 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20352 (A vulnerability in the RADIUS feature of Cisco Identity Services Engin ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20350 (A vulnerability in the web-based management interface of Cisco Thousan ...)
 	TODO: check
 CVE-2026-20344 (A vulnerability in the web-based management interface of Cisco Secure  ...)
@@ -435,35 +435,35 @@ CVE-2026-20330 (As part of Cisco's ongoing commitment to proactive security and
 CVE-2026-20329 (As part of Cisco's ongoing commitment to proactive security and produc ...)
 	TODO: check
 CVE-2026-20326 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20325 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20324 (A vulnerability in the sftunnel inter-device communication protocol of ...)
 	TODO: check
 CVE-2026-20323 (A vulnerability in the sftunnel inter-device communication protocol of ...)
 	TODO: check
 CVE-2026-20322 (As part of Cisco's ongoing commitment to proactive security and produc ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20309 (A vulnerability in the web-based management interface of Cisco Identit ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20300 (A vulnerability in Cisco ISE could allow an authenticated, remote atta ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20295 (A vulnerability in the sftunnel inter-device communication protocol of ...)
 	TODO: check
 CVE-2026-20290 (A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detectio ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20287 (As part of Cisco's ongoing commitment to proactive security and produc ...)
 	TODO: check
 CVE-2026-20286 (A vulnerability in the web-based management interface of Cisco Identif ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20285 (A vulnerability in the web-based management interface of Cisco Identit ...)
 	TODO: check
 CVE-2026-20284 (A vulnerability in the SXP REST API of Cisco ISE could allow an authen ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20283 (A vulnerability in the IPsec Open API endpoint of Cisco ISE could allo ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20282 (A vulnerability in Cisco ISE could allow an authenticated, remote atta ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20250 (A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secur ...)
 	TODO: check
 CVE-2026-20249 (A vulnerability in the certification authentication feature of Interne ...)
@@ -471,27 +471,27 @@ CVE-2026-20249 (A vulnerability in the certification authentication feature of I
 CVE-2026-20248 (A vulnerability in the DNS over TCP implementation of Cisco Secure Fir ...)
 	TODO: check
 CVE-2026-20247 (A vulnerability in Cisco ISE could allow an unauthenticated, remote at ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20242 (A vulnerability in the External Database Access feature of Cisco Secur ...)
 	TODO: check
 CVE-2026-20237 (As part of Cisco's ongoing commitment to proactive security and produc ...)
 	TODO: check
 CVE-2026-20235 (A vulnerability in the API of Cisco Identity Services Engine (ISE) cou ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20222 (A vulnerability in the EIGRP implementation in Cisco Secure Firewall A ...)
 	TODO: check
 CVE-2026-20211 (A vulnerability in Cisco ISE could allow an authenticated, remote atta ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20194 (As part of Cisco's ongoing commitment to proactive security and produc ...)
 	TODO: check
 CVE-2026-20192 (As part of Cisco's ongoing commitment to proactive security and produc ...)
 	TODO: check
 CVE-2026-20176 (A vulnerability in Cisco ISE could allow an authenticated, remote atta ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20154 (A vulnerability in the system rate-limiting process for syslog message ...)
 	TODO: check
 CVE-2026-20135 (A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20130 (As part of Cisco's ongoing commitment to proactive security and produc ...)
 	TODO: check
 CVE-2026-20121 (A vulnerability in the access control list (ACL) Object Group Search ( ...)
@@ -499,19 +499,19 @@ CVE-2026-20121 (A vulnerability in the access control list (ACL) Object Group Se
 CVE-2026-20120 (A vulnerability in the access control list (ACL) Object Group Search ( ...)
 	TODO: check
 CVE-2026-20072 (A vulnerability in the web-based management interface of Cisco ISE cou ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-20071 (A vulnerability in the SSID bring-your-own-device (BYOD) onboarding wo ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2025-59607 (Memory Corruption when copying large input data exceeds normal allocat ...)
-	TODO: check
+	NOT-FOR-US: Qualcomm
 CVE-2025-56566 (MikroTik firmware 7.19.4 stores sensitive authentication credentials a ...)
-	TODO: check
+	NOT-FOR-US: MikroTik
 CVE-2025-56565 (DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardwa ...)
-	TODO: check
+	NOT-FOR-US: TP-Link
 CVE-2025-56563 (A Server-Side Request Forgery vulnerability exists in sat_proxy.php in ...)
 	TODO: check
 CVE-2025-15697 (The Dictionary WordPress plugin through 1.0 does not escape user input ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-62846 [SQUID-2026:9]
 	- squid 7.7-1
 	TODO: check SQUID-2026:9 information not yet public



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac210c5093820990b00a8185d85e794abb279399

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac210c5093820990b00a8185d85e794abb279399
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/03fcb3cd/attachment.htm>


More information about the debian-security-tracker-commits mailing list