[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 17 17:32:32 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8b898d3b by Moritz Muehlenhoff at 2026-09-17T18:32:08+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -172,11 +172,11 @@ CVE-2026-92527 (A vulnerability has been found in chatwoot up to 4.17.1. This im
CVE-2026-92526 (A flaw has been found in itsourcecode Leave Management System 1.0. Thi ...)
NOT-FOR-US: itsourcecode System
CVE-2026-92475 (A weakness has been identified in GPAC 26.08-DEV. This impacts the fun ...)
- TODO: check
+ - gpac <removed>
CVE-2026-92474 (A security flaw has been discovered in GPAC 26.08-DEV. This affects th ...)
- TODO: check
+ - gpac <removed>
CVE-2026-92473 (A vulnerability was identified in GPAC 26.08-DEV. The impacted element ...)
- TODO: check
+ - gpac <removed>
CVE-2026-91019 (The Event Booking Manager for WooCommerce WordPress plugin before 5.6 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-91017 (The Robokassa payment gateway for Woocommerce WordPress plugin before ...)
@@ -196,7 +196,7 @@ CVE-2026-91009 (The Active Woot Products Tables for WooCommerce. 100% FREE WordP
CVE-2026-91008 (The Event Booking Manager for WooCommerce WordPress plugin before 5.3 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-90982 (@fastify/static is a Fastify plugin that serves static files from a co ...)
- TODO: check
+ NOT-FOR-US: Fastify plugin
CVE-2026-90923 (The Autopay WordPress plugin before 5.0.1 does not enforce the signatu ...)
NOT-FOR-US: WordPress plugin
CVE-2026-90922 (The Paid Membership Subscriptions WordPress plugin before 3.0.9 does ...)
@@ -294,47 +294,47 @@ CVE-2026-76646 (A remote attacker could cause excessive resource consumption by
CVE-2026-76460 (A vulnerability in an API of Cisco Identity Services Engine (ISE) coul ...)
TODO: check
CVE-2026-76451 (A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76450 (A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76449 (A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76448 (A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76447 (A vulnerability in the Online Certificate Status Protocol (OCSP) respo ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76446 (A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow a ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76444 (A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76439 (A vulnerability in the endpoint posture status reporting functionality ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76438 (A vulnerability in the web-based management interface of Cisco BroadWo ...)
NOT-FOR-US: Cisco
CVE-2026-76434 (A vulnerability in the certificate import functionality of the web-bas ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76433 (A vulnerability in the client provisioning download feature of Cisco I ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76432 (A vulnerability in the web-based management interface of Cisco ISE and ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76431 (A vulnerability in the file management function of the web-based manag ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76428 (A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76427 (A vulnerability in the offline profiler feed service of Cisco ISE coul ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76426 (A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could a ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76425 (A vulnerability in the APIs of Cisco ISE could allow an authenticated, ...)
NOT-FOR-US: Cisco
CVE-2026-76424 (A vulnerability in the REST API of Cisco ISE could allow an authentica ...)
NOT-FOR-US: Cisco
CVE-2026-76423 (A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could a ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76413 (A vulnerability in Cisco Adaptive Security Device Manager (ASDM) singl ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76412 (A vulnerability in the remote diagnostics debugger of Cisco Secure FMC ...)
- TODO: check
+ NOT-FOR-US: Cisco
CVE-2026-76409 (As part of Cisco's ongoing commitment to proactive security and produc ...)
NOT-FOR-US: Cisco
CVE-2026-75513 (Marten is a .NET Transactional Document DB and Event Store on PostgreS ...)
@@ -358,27 +358,27 @@ CVE-2026-62997 (Kedro-Datasets provides data connectors for Kedro. From version
CVE-2026-62949 (AsyncSSH is a Python package which provides an asynchronous client and ...)
TODO: check
CVE-2026-61599 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
- TODO: check
+ NOT-FOR-US: djust
CVE-2026-61597 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
- TODO: check
+ NOT-FOR-US: djust
CVE-2026-61596 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
- TODO: check
+ NOT-FOR-US: djust
CVE-2026-61594 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
- TODO: check
+ NOT-FOR-US: djust
CVE-2026-61592 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
- TODO: check
+ NOT-FOR-US: djust
CVE-2026-61591 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
- TODO: check
+ NOT-FOR-US: djust
CVE-2026-61589 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
- TODO: check
+ NOT-FOR-US: djust
CVE-2026-61588 (djust provides Phoenix LiveView-style reactive server-side rendering f ...)
- TODO: check
+ NOT-FOR-US: djust
CVE-2026-50604 (A vulnerability has been identified in the Acer Agent Service componen ...)
NOT-FOR-US: Acer
CVE-2026-50603 (A vulnerability has been identified in the Acer Agent Service componen ...)
NOT-FOR-US: Acer
CVE-2026-44940 (The rancher-extension-stackstate extension in SUSE Observability expos ...)
- TODO: check
+ NOT-FOR-US: SuSE
CVE-2026-25294 (Transient DOS while parsing frame during channel usage.)
NOT-FOR-US: Qualcomm
CVE-2026-25290 (Memory Corruption when validating large data buffers from external sou ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8b898d3b1e4631d4fd93ebbd1c44c2f4395d235b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8b898d3b1e4631d4fd93ebbd1c44c2f4395d235b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/938a6062/attachment.htm>
More information about the debian-security-tracker-commits
mailing list