[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Tue Sep 22 22:22:41 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ba1a23dd by Moritz Muehlenhoff at 2026-09-22T23:22:09+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -147,7 +147,7 @@ CVE-2026-91092 (The wpForo Forum plugin for WordPress is vulnerable to authoriza
CVE-2026-90990 (Improper neutralization of newlines in filter values in the monitoring ...)
NOT-FOR-US: Checkmk
CVE-2026-90882 (The open-vsx.org deployment returned Access-Control-Allow-Origin refle ...)
- TODO: check
+ NOT-FOR-US: open-vsx.org
CVE-2026-90462 (A flaw was found in SSSD. When configured with the LDAP access provide ...)
- sssd <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479483
@@ -277,31 +277,31 @@ CVE-2026-81879 (radare2 is a UNIX-like reverse engineering framework and command
CVE-2026-81878 (radare2 is a UNIX-like reverse engineering framework and command-line ...)
TODO: check
CVE-2026-80156 (Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before fir ...)
- TODO: check
+ NOT-FOR-US: Lantronix
CVE-2026-80155 (Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before fir ...)
- TODO: check
+ NOT-FOR-US: Lantronix
CVE-2026-80154 (All firmware versions of Lantronix SLC8000, EMG8500, EMG7500, SLB882, ...)
- TODO: check
+ NOT-FOR-US: Lantronix
CVE-2026-80152 (Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before fir ...)
- TODO: check
+ NOT-FOR-US: Lantronix
CVE-2026-80151 (Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before fir ...)
- TODO: check
+ NOT-FOR-US: Lantronix
CVE-2026-80150 (Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before fir ...)
- TODO: check
+ NOT-FOR-US: Lantronix
CVE-2026-80149 (Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before fir ...)
- TODO: check
+ NOT-FOR-US: Lantronix
CVE-2026-80148 (Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before fir ...)
- TODO: check
+ NOT-FOR-US: Lantronix
CVE-2026-80147 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
- TODO: check
+ NOT-FOR-US: Lantronix
CVE-2026-80146 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
- TODO: check
+ NOT-FOR-US: Lantronix
CVE-2026-80145 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
- TODO: check
+ NOT-FOR-US: Lantronix
CVE-2026-80144 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
- TODO: check
+ NOT-FOR-US: Lantronix
CVE-2026-80143 (Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before fir ...)
- TODO: check
+ NOT-FOR-US: Lantronix
CVE-2026-7866 (Stack-based Buffer Overflow vulnerability in RTI Connext Professional ...)
NOT-FOR-US: RTI Connext
CVE-2026-7622 (The ThumbPress plugin for WordPress is vulnerable to unauthorized acce ...)
@@ -311,9 +311,9 @@ CVE-2026-79913 (Cloudreve is a self-hosted file management and sharing system. P
CVE-2026-79906 (Substance3D - Modeler is affected by an out-of-bounds write vulnerabil ...)
NOT-FOR-US: Adobe
CVE-2026-79315 (A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. T ...)
- TODO: check
+ NOT-FOR-US: x-ui
CVE-2026-79314 (A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. ...)
- TODO: check
+ NOT-FOR-US: x-ui
CVE-2026-79313 (webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. Th ...)
TODO: check
CVE-2026-79312 (webpy web.py 0.76 is vulnerable to Session Fixation. The component Ses ...)
@@ -321,17 +321,17 @@ CVE-2026-79312 (webpy web.py 0.76 is vulnerable to Session Fixation. The compone
CVE-2026-79311 (webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via rend ...)
TODO: check
CVE-2026-77637 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
- TODO: check
+ NOT-FOR-US: Cloudreve
CVE-2026-77633 (Cloudreve is a self-hosted file management and sharing system. Prior t ...)
- TODO: check
+ NOT-FOR-US: Cloudreve
CVE-2026-77621 (Vector is a high-performance observability data pipeline. From 0.10.0 ...)
- TODO: check
+ NOT-FOR-US: Vector
CVE-2026-77620 (Vector is a high-performance observability data pipeline. From 0.15.0 ...)
- TODO: check
+ NOT-FOR-US: Vector
CVE-2026-77619 (Vector is a high-performance observability data pipeline. From 0.15.0 ...)
- TODO: check
+ NOT-FOR-US: Vector
CVE-2026-77605 (Notepad++ is a free and open-source source code editor. Prior to 8.9.8 ...)
- TODO: check
+ NOT-FOR-US: Notepad++
CVE-2026-77558 (A malicious actor with access to the network could exploit an Out-of-b ...)
NOT-FOR-US: Ubiquity
CVE-2026-77556 (A malicious actor with access to the network could exploit an Out-of-b ...)
@@ -403,13 +403,13 @@ CVE-2026-77242 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlas
CVE-2026-76819
REJECTED
CVE-2026-76805 (Nuclei is a vulnerability scanner built on a simple YAML-based DSL. Fr ...)
- TODO: check
+ NOT-FOR-US: Nuclei
CVE-2026-76804 (Nuclei is a vulnerability scanner built on a simple YAML-based DSL. Fr ...)
- TODO: check
+ NOT-FOR-US: Nuclei
CVE-2026-76803 (Nuclei is a vulnerability scanner built on a simple YAML-based DSL. Fr ...)
- TODO: check
+ NOT-FOR-US: Nuclei
CVE-2026-76802 (Nuclei is a vulnerability scanner built on a simple YAML-based DSL. Fr ...)
- TODO: check
+ NOT-FOR-US: Nuclei
CVE-2026-76194 (CAI Content Credentials is affected by an Improper Input Validation vu ...)
NOT-FOR-US: Adobe
CVE-2026-76192 (InDesign Desktop is affected by a NULL Pointer Dereference vulnerabili ...)
@@ -467,15 +467,15 @@ CVE-2026-75633 (CAI Content Credentials is affected by an Improper Input Validat
CVE-2026-75632 (CAI Content Credentials is affected by an Uncontrolled Resource Consum ...)
NOT-FOR-US: Adobe
CVE-2026-75608 (Frigate is an open source network video recorder. Prior to 0.18.0, the ...)
- TODO: check
+ NOT-FOR-US: Frigate
CVE-2026-75607 (Frigate is an open source network video recorder. Prior to 0.17.2, the ...)
- TODO: check
+ NOT-FOR-US: Frigate
CVE-2026-75517 (Novu provides an API for sending notifications through multiple channe ...)
- TODO: check
+ NOT-FOR-US: Novu
CVE-2026-75511 (Novu provides an API for sending notifications through multiple channe ...)
- TODO: check
+ NOT-FOR-US: Novu
CVE-2026-75510 (Novu provides an API for sending notifications through multiple channe ...)
- TODO: check
+ NOT-FOR-US: Novu
CVE-2026-74849 (Zohocorp ManageEngine ADSelfService Plus versions before build 7001 ar ...)
NOT-FOR-US: Zoho
CVE-2026-73369 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
@@ -546,7 +546,7 @@ CVE-2026-63272 (LibreOffice can import WMF graphics, which may be embedded in do
- libreoffice 4:26.2.5.2-1
NOTE: https://www.libreoffice.org/security/#cve-2026-63272
CVE-2026-57149 (plone.app.portlets.portlets provides a Plone-specific user interface f ...)
- TODO: check
+ NOT-FOR-US: plone.app.portlets.portlets
CVE-2026-56682 (9Router is an AI router & token saver. Prior to 0.5.6, 9Router deploym ...)
NOT-FOR-US: Next.js
CVE-2026-56681 (9Router is an AI router & token saver. Prior to 0.5.6, 9Router deploym ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ba1a23dd3eb890b1270de349bcbb6470fc5406ed
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ba1a23dd3eb890b1270de349bcbb6470fc5406ed
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/359ec717/attachment.htm>
More information about the debian-security-tracker-commits
mailing list