[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 22 22:22:41 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ba1a23dd by Moritz Muehlenhoff at 2026-09-22T23:22:09+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -147,7 +147,7 @@ CVE-2026-91092 (The wpForo Forum plugin for WordPress is vulnerable to authoriza
 CVE-2026-90990 (Improper neutralization of newlines in filter values in the monitoring ...)
 	NOT-FOR-US: Checkmk
 CVE-2026-90882 (The open-vsx.org deployment returned Access-Control-Allow-Origin refle ...)
-	TODO: check
+	NOT-FOR-US: open-vsx.org
 CVE-2026-90462 (A flaw was found in SSSD. When configured with the LDAP access provide ...)
 	- sssd <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479483
@@ -277,31 +277,31 @@ CVE-2026-81879 (radare2 is a UNIX-like reverse engineering framework and command
 CVE-2026-81878 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
 	TODO: check
 CVE-2026-80156 (Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before fir ...)
-	TODO: check
+	NOT-FOR-US: Lantronix
 CVE-2026-80155 (Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before fir ...)
-	TODO: check
+	NOT-FOR-US: Lantronix
 CVE-2026-80154 (All firmware versions of Lantronix SLC8000, EMG8500, EMG7500, SLB882,  ...)
-	TODO: check
+	NOT-FOR-US: Lantronix
 CVE-2026-80152 (Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before fir ...)
-	TODO: check
+	NOT-FOR-US: Lantronix
 CVE-2026-80151 (Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before fir ...)
-	TODO: check
+	NOT-FOR-US: Lantronix
 CVE-2026-80150 (Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before fir ...)
-	TODO: check
+	NOT-FOR-US: Lantronix
 CVE-2026-80149 (Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before fir ...)
-	TODO: check
+	NOT-FOR-US: Lantronix
 CVE-2026-80148 (Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before fir ...)
-	TODO: check
+	NOT-FOR-US: Lantronix
 CVE-2026-80147 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
-	TODO: check
+	NOT-FOR-US: Lantronix
 CVE-2026-80146 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
-	TODO: check
+	NOT-FOR-US: Lantronix
 CVE-2026-80145 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
-	TODO: check
+	NOT-FOR-US: Lantronix
 CVE-2026-80144 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
-	TODO: check
+	NOT-FOR-US: Lantronix
 CVE-2026-80143 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
-	TODO: check
+	NOT-FOR-US: Lantronix
 CVE-2026-7866 (Stack-based Buffer Overflow vulnerability in RTI Connext Professional  ...)
 	NOT-FOR-US: RTI Connext
 CVE-2026-7622 (The ThumbPress plugin for WordPress is vulnerable to unauthorized acce ...)
@@ -311,9 +311,9 @@ CVE-2026-79913 (Cloudreve is a self-hosted file management and sharing system. P
 CVE-2026-79906 (Substance3D - Modeler is affected by an out-of-bounds write vulnerabil ...)
 	NOT-FOR-US: Adobe
 CVE-2026-79315 (A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. T ...)
-	TODO: check
+	NOT-FOR-US: x-ui
 CVE-2026-79314 (A horizontal privilege escalation vulnerability exists in x-ui 0.3.2.  ...)
-	TODO: check
+	NOT-FOR-US: x-ui
 CVE-2026-79313 (webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. Th ...)
 	TODO: check
 CVE-2026-79312 (webpy web.py 0.76 is vulnerable to Session Fixation. The component Ses ...)
@@ -321,17 +321,17 @@ CVE-2026-79312 (webpy web.py 0.76 is vulnerable to Session Fixation. The compone
 CVE-2026-79311 (webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via rend ...)
 	TODO: check
 CVE-2026-77637 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
-	TODO: check
+	NOT-FOR-US: Cloudreve
 CVE-2026-77633 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
-	TODO: check
+	NOT-FOR-US: Cloudreve
 CVE-2026-77621 (Vector is a high-performance observability data pipeline. From 0.10.0  ...)
-	TODO: check
+	NOT-FOR-US: Vector
 CVE-2026-77620 (Vector is a high-performance observability data pipeline. From 0.15.0  ...)
-	TODO: check
+	NOT-FOR-US: Vector
 CVE-2026-77619 (Vector is a high-performance observability data pipeline. From 0.15.0  ...)
-	TODO: check
+	NOT-FOR-US: Vector
 CVE-2026-77605 (Notepad++ is a free and open-source source code editor. Prior to 8.9.8 ...)
-	TODO: check
+	NOT-FOR-US: Notepad++
 CVE-2026-77558 (A malicious actor with access to the network could exploit an Out-of-b ...)
 	NOT-FOR-US: Ubiquity
 CVE-2026-77556 (A malicious actor with access to the network could exploit an Out-of-b ...)
@@ -403,13 +403,13 @@ CVE-2026-77242 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlas
 CVE-2026-76819
 	REJECTED
 CVE-2026-76805 (Nuclei is a vulnerability scanner built on a simple YAML-based DSL. Fr ...)
-	TODO: check
+	NOT-FOR-US: Nuclei
 CVE-2026-76804 (Nuclei is a vulnerability scanner built on a simple YAML-based DSL. Fr ...)
-	TODO: check
+	NOT-FOR-US: Nuclei
 CVE-2026-76803 (Nuclei is a vulnerability scanner built on a simple YAML-based DSL. Fr ...)
-	TODO: check
+	NOT-FOR-US: Nuclei
 CVE-2026-76802 (Nuclei is a vulnerability scanner built on a simple YAML-based DSL. Fr ...)
-	TODO: check
+	NOT-FOR-US: Nuclei
 CVE-2026-76194 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
 	NOT-FOR-US: Adobe
 CVE-2026-76192 (InDesign Desktop is affected by a NULL Pointer Dereference vulnerabili ...)
@@ -467,15 +467,15 @@ CVE-2026-75633 (CAI Content Credentials is affected by an Improper Input Validat
 CVE-2026-75632 (CAI Content Credentials is affected by an Uncontrolled Resource Consum ...)
 	NOT-FOR-US: Adobe
 CVE-2026-75608 (Frigate is an open source network video recorder. Prior to 0.18.0, the ...)
-	TODO: check
+	NOT-FOR-US: Frigate
 CVE-2026-75607 (Frigate is an open source network video recorder. Prior to 0.17.2, the ...)
-	TODO: check
+	NOT-FOR-US: Frigate
 CVE-2026-75517 (Novu provides an API for sending notifications through multiple channe ...)
-	TODO: check
+	NOT-FOR-US: Novu
 CVE-2026-75511 (Novu provides an API for sending notifications through multiple channe ...)
-	TODO: check
+	NOT-FOR-US: Novu
 CVE-2026-75510 (Novu provides an API for sending notifications through multiple channe ...)
-	TODO: check
+	NOT-FOR-US: Novu
 CVE-2026-74849 (Zohocorp ManageEngine ADSelfService Plus versions before build 7001 ar ...)
 	NOT-FOR-US: Zoho
 CVE-2026-73369 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
@@ -546,7 +546,7 @@ CVE-2026-63272 (LibreOffice can import WMF graphics, which may be embedded in do
 	- libreoffice 4:26.2.5.2-1
 	NOTE: https://www.libreoffice.org/security/#cve-2026-63272
 CVE-2026-57149 (plone.app.portlets.portlets provides a Plone-specific user interface f ...)
-	TODO: check
+	NOT-FOR-US: plone.app.portlets.portlets
 CVE-2026-56682 (9Router is an AI router & token saver. Prior to 0.5.6, 9Router deploym ...)
 	NOT-FOR-US: Next.js
 CVE-2026-56681 (9Router is an AI router & token saver. Prior to 0.5.6, 9Router deploym ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ba1a23dd3eb890b1270de349bcbb6470fc5406ed

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ba1a23dd3eb890b1270de349bcbb6470fc5406ed
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/359ec717/attachment.htm>


More information about the debian-security-tracker-commits mailing list