[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 24 08:14:12 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
29435e19 by security tracker role at 2026-09-24T07:14:04+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -19,9 +19,9 @@ CVE-2026-97055 (SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer si
 CVE-2026-96898 (A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected ...)
 	TODO: check
 CVE-2026-96892 (A flaw has been found in Edimax BR-6428nC 1.16. The impacted element i ...)
-	TODO: check
+	NOT-FOR-US: Edimax
 CVE-2026-96891 (A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is  ...)
-	TODO: check
+	NOT-FOR-US: D-Link
 CVE-2026-96889 (A flaw was found in librsvg. When processing an SVG document containin ...)
 	TODO: check
 CVE-2026-96884 (A security flaw has been discovered in MantisZip up to 0.4.5. Affected ...)
@@ -33,19 +33,19 @@ CVE-2026-96881 (A vulnerability was determined in TaleLin lin-cms-spring-boot up
 CVE-2026-96880 (A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1.  ...)
 	TODO: check
 CVE-2026-96872 (Improper handling of insufficient permissions or privileges vulnerabil ...)
-	TODO: check
+	NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
 CVE-2026-96826 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-96810 (A vulnerability was identified in huanzi-qch base-admin up to 52816b76 ...)
 	TODO: check
 CVE-2026-96804 (MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW ...)
-	TODO: check
+	NOT-FOR-US: mlflow
 CVE-2026-96803 (A vulnerability was identified in java110 MicroCommunity up to 2.0. Af ...)
 	TODO: check
 CVE-2026-96777 (A vulnerability was determined in Forma LMS up to 4.1.43. This impacts ...)
 	TODO: check
 CVE-2026-96775 (MLflow's dspy flavor, versions >= 2.0,  applies the MLFLOW_ALLOW_PICKL ...)
-	TODO: check
+	NOT-FOR-US: mlflow
 CVE-2026-96774 (A vulnerability was found in SPON Communications IP Network Audio Devi ...)
 	TODO: check
 CVE-2026-96773 (A weakness has been identified in Intelliants Subrion CMS up to 4.2.1. ...)
@@ -53,7 +53,7 @@ CVE-2026-96773 (A weakness has been identified in Intelliants Subrion CMS up to
 CVE-2026-96772 (A security flaw has been discovered in Intelliants Subrion CMS up to 4 ...)
 	TODO: check
 CVE-2026-96770 (All published s2s-proxy versions through 0.2.2 are affected. In versio ...)
-	TODO: check
+	NOT-FOR-US: Temporal Technologies
 CVE-2026-96764 (A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3 ...)
 	TODO: check
 CVE-2026-96763 (A security flaw has been discovered in kvcache-ai mooncake up to 0.3.1 ...)
@@ -157,7 +157,7 @@ CVE-2026-96446 (A flaw was found in the Pushed Authorization Request PAR impleme
 CVE-2026-96445 (A flaw was found in the Conditional OTP authenticator of Keycloak, an  ...)
 	TODO: check
 CVE-2026-96443 (Insufficient validation of the JDBC driver URL in Apache Doris allows  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-96442 (A code execution flaw was found in Emacs, affecting versions prior to  ...)
 	TODO: check
 CVE-2026-95848 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a co ...)
@@ -175,7 +175,7 @@ CVE-2026-95843 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Pos
 CVE-2026-95842 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEv ...)
 	TODO: check
 CVE-2026-95676 (A missing/improper authentication vulnerability in the WatchGuard Auth ...)
-	TODO: check
+	NOT-FOR-US: WatchGuard
 CVE-2026-95627 (When a Tauri application uses the dialog plugin's file or folder picke ...)
 	TODO: check
 CVE-2026-95626 (Tauri's Content Security Policy hardening, which injects a random nonc ...)
@@ -183,67 +183,67 @@ CVE-2026-95626 (Tauri's Content Security Policy hardening, which injects a rando
 CVE-2026-95625 (The Tauri updater plugin verifies update binaries using minisign signa ...)
 	TODO: check
 CVE-2026-95604 (Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95603 (Shop manager PHP Object Injection in Reycob Product Import Export <= 2 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95602 (Authorization Bypass Through User-Controlled Key vulnerability in YITH ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95601 (Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versio ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95600 (Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95593 (Editor SQL Injection in Ultimeter <= 3.0.8 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95592 (Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95590 (Subscriber SQL Injection in Tainacan <= 1.2.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95586 (Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95530 (Subscriber Cross Site Scripting (XSS) in PixelYourSite \u2013 Your sma ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95529 (Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form < ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95528 (Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSp ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95527 (Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95525 (Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95524 (Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95523 (Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95522 (Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95515 (Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 ve ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95514 (Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95513 (Unauthenticated Broken Access Control in Online Booking & Scheduling C ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94684 (Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 version ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94682 (Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94680 (Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94679 (Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94671 (Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94500 (Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94498 (Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94487 (Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capa ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94461 (Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94457 (Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94391 (Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94251 (A vulnerability in Apache Sling Security Bundle:ContentDispositionFilt ...)
 	TODO: check
 CVE-2026-94243 (A vulnerability in Apache Sling Security Bundle: the ReferrerFilter ac ...)
@@ -253,61 +253,61 @@ CVE-2026-94183 (Arc Search for Android before version 1.12.10 does not display a
 CVE-2026-94181 (An address bar spoofing issue in affected versions of Arc could allow  ...)
 	TODO: check
 CVE-2026-94179 (Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94176 (Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94174 (Administrator SQL Injection in Email Log <= 2.63 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94168 (Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94124 (Contributor SQL Injection in WP EasyCart <= 5.9.4 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94118 (Contributor Cross Site Scripting (XSS) in Premium Blocks \u2013 Gutenb ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94080 (Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94079 (Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93774 (Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93773 (Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93772 (Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 version ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93769 (HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulne ...)
 	TODO: check
 CVE-2026-93662 (The Events Manager  WordPress plugin before 7.4.5 does not force the s ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93661 (The Events Manager  WordPress plugin before 7.4.5 does not stop a tick ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93623 (Unauthenticated Insecure Direct Object References (IDOR) in AI Engine  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93622 (Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93620 (Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93618 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93577 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-93529 (Contributor Broken Access Control in WSP MCP – AI Agents Connect ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93527 (Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93526 (Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93513 (Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-93421 (Mesop is a Python-based UI framework that allows users to build web ap ...)
 	TODO: check
 CVE-2026-93368 (The Rename wp-login.php to anything you want plugin for WordPress is v ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-93352 (Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for C ...)
 	TODO: check
 CVE-2026-93349 (Frictionless through 5.20.0rc1 contains an OS command injection vulner ...)
 	TODO: check
 CVE-2026-92874 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-92730 (LimeSurvey Community Edition 7.0.14 contains a reflected cross-site sc ...)
 	TODO: check
 CVE-2026-92700 (Caddy is an extensible server platform that uses TLS by default. In ve ...)
@@ -315,17 +315,17 @@ CVE-2026-92700 (Caddy is an extensible server platform that uses TLS by default.
 CVE-2026-92692 (Sulu is an open-source PHP content management system based on the Symf ...)
 	TODO: check
 CVE-2026-92628 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-92530 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-92529 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-92470 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-92419 (WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in ...)
 	TODO: check
 CVE-2026-92378 (A session management vulnerability exists in the Legacy UI Reduced Fun ...)
-	TODO: check
+	NOT-FOR-US: Canon
 CVE-2026-92284 (Caddy is an extensible server platform that uses TLS by default. In ve ...)
 	TODO: check
 CVE-2026-92164 (Streamlink is a CLI utility which pipes video streams from various ser ...)
@@ -339,103 +339,103 @@ CVE-2026-91928 (Improper neutralization of input during web page generation ('cr
 CVE-2026-91852 (Improper neutralization of input during web page generation ('cross-si ...)
 	TODO: check
 CVE-2026-91818 (A use-after-free vulnerability exists in Foxit PDF Editor/Reader\u2019 ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91817 (A heap-based out-of-bounds read vulnerability exists in Foxit PDF Edit ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91816 (A use-after-free vulnerability exists in Foxit PDF Editor/Reader\u2019 ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91815 (Foxit PDF Editor/Reader does not perform sufficient verification of th ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91814 (A signature validation vulnerability exists in Foxit PDF Editor/Reader ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91813 (A vulnerability in Foxit PDF Editor/Reader\u2019s update mechanism all ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91812 (A vulnerability in Foxit PDF Editor/Reader\u2019s update mechanism all ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91811 (A heap-based out-of-bounds write vulnerability exists in Foxit PDF Edi ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91810 (A heap-based out-of-bounds read vulnerability exists in Foxit PDF Edit ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91809 (A use-after-free vulnerability exists in Foxit PDF Editor/Reader\u2019 ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91808 (A heap-based out-of-bounds read vulnerability exists in Foxit PDF Edit ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91807 (A heap-based out-of-bounds read vulnerability exists in Foxit PDF Edit ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91806 (A use-after-free vulnerability exists in Foxit PDF Editor/Reader\u2019 ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91805 (A use-after-free vulnerability exists in Foxit PDF Editor/Reader\u2019 ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91804 (A heap-based out-of-bounds write vulnerability exists in Foxit PDF Edi ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91803 (A local privilege escalation vulnerability exists in the updater of Fo ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91802 (A heap-based out-of-bounds write vulnerability exists in Foxit PDF Edi ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91801 (A path traversal vulnerability exists in Foxit PDF Editor/Reader's han ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91800 (A local privilege escalation vulnerability exists in the installer of  ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91799 (A use-after-free vulnerability exists in Foxit PDF Editor/Reader\u2019 ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91798 (A local privilege escalation vulnerability exists in the update daemon ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91797 (Foxit PDF Editor/Reader failed to validate the directory traversal pat ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91796 (The interface of Foxit PDF Editor/Reader lacks the permission verifica ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91795 (Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate  ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91794 (An out-of-bounds write vulnerability exists in the PDF rendering proce ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91793 (When opening a specially crafted PDF, Foxit PDF Editor/Reader executes ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91792 (When processing a specially crafted PDF, Foxit PDF Editor/Reader may p ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91791 (When processing a specially crafted PDF file, Foxit PDF Editor/Reader  ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91790 (When rendering the page image, Foxit PDF Editor/Reader fails to perfor ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91789 (Foxit PDF Editor/Reader\u2019s U3D/GIF texture decoding path contained ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91788 (When implementing the JavaScript interface, Foxit PDF Editor/Reader di ...)
-	TODO: check
+	NOT-FOR-US: Foxit
 CVE-2026-91775 (LimeSurvey fails to safely encode attacker-controlled content from a c ...)
 	TODO: check
 CVE-2026-90950 (The Paid Membership Subscriptions WordPress plugin before 3.1.0 does n ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-90905 (Joomla Extension - joomshaper.com - Missing CSRF and Access Control on ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-90904 (Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-90903 (Joomla Extension - joomshaper.com - Missing CSRF Token Verification ac ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-90902 (Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Inje ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-90901 (Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Inje ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-90900 (Joomla Extension - joomshaper.com - Missing CSRF Token Verification in ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-90899 (Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via I ...)
-	TODO: check
+	NOT-FOR-US: Joomla
 CVE-2026-89078 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
-	TODO: check
+	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-89005 (The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-89004 (The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-89002 (The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-88974 (WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, ...)
 	TODO: check
 CVE-2026-88847 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-88846 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-88845 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-88843 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 d ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-88840 (BusyBox TLS get_client_hello() reads past the end of the input buffer  ...)
 	TODO: check
 CVE-2026-88839 (BusyBox passwd/group tokenize() references a stale endpoint pointer af ...)
@@ -451,7 +451,7 @@ CVE-2026-88831 (BusyBox httpd IP deny rules with invalid CIDR prefix lengths fai
 CVE-2026-88830 (A unit confusion in BusyBox TLS Montgomery reduction buffer allocation ...)
 	TODO: check
 CVE-2026-87978 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does not ver ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87900 (Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier a ...)
 	TODO: check
 CVE-2026-87899 (Execution with unnecessary privileges in cPanel allows remote authenti ...)
@@ -459,43 +459,43 @@ CVE-2026-87899 (Execution with unnecessary privileges in cPanel allows remote au
 CVE-2026-87898 (OS command injection in Plesk allows remote authenticated users to exe ...)
 	TODO: check
 CVE-2026-87848 (The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have a ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87739 (An improper authentication vulnerability in PaperCut MF/NG allows an u ...)
 	TODO: check
 CVE-2026-87071 (The Forminator Forms WordPress plugin before 1.57.2.1 does not restric ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-87070 (The Forminator Forms WordPress plugin before 1.57.2.1 does not verify  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86938 (A DLL hijacking vulnerability in the FileMaker Pro installer for Windo ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-86934 (An authorization bypass vulnerability in the FileMaker Server Web Publ ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-86930 (An out-of-bounds read vulnerability in FileMaker Server for Linux allo ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-86926 (A heap buffer overflow vulnerability in the FileMaker Server database  ...)
-	TODO: check
+	NOT-FOR-US: Apple
 CVE-2026-86867 (Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-u ...)
 	TODO: check
 CVE-2026-86708 (ZohoCorp ManageEngine Applications Manager versions 182200 and below w ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-86683 (ZohoCorp ManageEngine Applications Manager versions 182000 and below a ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-86681 (ZohoCorp ManageEngine Applications Manager versions 182200 and below w ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-86679 (ZohoCorp ManageEngine Applications Manager versions 182000 and below w ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-86678 (ZohoCorp ManageEngine Applications Manager versions 182000 and below a ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-86677 (ZohoCorp ManageEngine Applications Manager versions 182000 and below a ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-86612 (The Ninja Tables WordPress plugin before 5.2.17 does not restrict shor ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86604 (The GTranslate WordPress plugin before 5.0.1 does not remove shortcode ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86601 (The WP Recipe Maker WordPress plugin before 10.8.2 does not remove sho ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86583 (The Import and export users and customers plugin for WordPress is vuln ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-86065 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
 	TODO: check
 CVE-2026-86064 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
@@ -505,11 +505,11 @@ CVE-2026-85724 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, whe
 CVE-2026-85475 (A flaw was found in the Ansible Automation Platform automation control ...)
 	TODO: check
 CVE-2026-84791 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.71 ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-84789 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.71 ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-84787 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.71 ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-84724 (An argument-injection flaw was found in the Ansible Automation Platfor ...)
 	TODO: check
 CVE-2026-84721 (A server-side request forgery flaw was found in the Ansible Automation ...)
@@ -545,13 +545,13 @@ CVE-2026-84486 (A flaw was found in Red Hat Ansible Automation Platform's automa
 CVE-2026-84474 (A flaw was found in Red Hat Ansible Automation Platform's automation-  ...)
 	TODO: check
 CVE-2026-84151 (The Post Grid  WordPress plugin before 7.9.5 does not limit an expansi ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-84091 (The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82850 (The Masteriyo LMS  WordPress plugin before 3.4.2 does not restrict acc ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82849 (The Masteriyo LMS  WordPress plugin before 3.4.2 does not verify that  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82409 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
 	TODO: check
 CVE-2026-82407 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
@@ -561,39 +561,39 @@ CVE-2026-82406 (Klever-Go is the Go implementation of the Klever blockchain prot
 CVE-2026-82405 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
 	TODO: check
 CVE-2026-82370 (Unauthenticated remote command injection in the Brocade SANnav orchest ...)
-	TODO: check
+	NOT-FOR-US: Brocade
 CVE-2026-82369 (Insufficient input sanitization of shell metacharacters in the Brocade ...)
-	TODO: check
+	NOT-FOR-US: Brocade
 CVE-2026-82368 (Insecure access controls on internal service ports in Brocade SANnav v ...)
-	TODO: check
+	NOT-FOR-US: Brocade
 CVE-2026-82356 (Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair af ...)
 	TODO: check
 CVE-2026-82195 (The 10Web Booster  WordPress plugin before 2.34.0 does not restrict ac ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-82077 (An improper limitation of a pathname to a restricted directory (path t ...)
 	TODO: check
 CVE-2026-81645 (Out-of-bounds read vulnerability in the graphics module.Successful exp ...)
-	TODO: check
+	NOT-FOR-US: Huawei
 CVE-2026-81537 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-81536 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-81208 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticat ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-80513 (The wpForo Forum WordPress plugin before 3.1.6 does not restrict which ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-80444 (URL redirection to untrusted site ('open redirect') vulnerability in A ...)
 	TODO: check
 CVE-2026-80425 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-80423 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-80412 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-80379 (IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authe ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-80338 (The CMB2 WordPress plugin before 2.13.0 does not perform any capabilit ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-79616 (Out-of-bounds read while parsing untrusted SVG path strings in Qt Quic ...)
 	TODO: check
 CVE-2026-79310 (webpy web.py 0.76 is vulnerable to server-side template injection (SST ...)
@@ -623,19 +623,19 @@ CVE-2026-77285 (OpenBao is an open source identity-based secrets management syst
 CVE-2026-77112 (Server-Side request forgery (SSRF) vulnerability in Global IT Informat ...)
 	TODO: check
 CVE-2026-76980 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.70 ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-76979 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.70 ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-76978 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.70 ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-76648 (CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (I ...)
 	TODO: check
 CVE-2026-76089 (Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3 ...)
-	TODO: check
+	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-76087 (Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3 ...)
-	TODO: check
+	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-76086 (Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3 ...)
-	TODO: check
+	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-75887 (A flaw was found in the OpenShift console. An unauthenticated attacker ...)
 	TODO: check
 CVE-2026-75886 (A flaw was found in openshift/console. An unauthenticated remote attac ...)
@@ -643,21 +643,21 @@ CVE-2026-75886 (A flaw was found in openshift/console. An unauthenticated remote
 CVE-2026-75884 (A flaw was found in AWX. The container group pod_spec_override field u ...)
 	TODO: check
 CVE-2026-75825 (ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the A ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-74991 (The WPForms  WordPress plugin before 2.0.2 does not verify that a Stri ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-73858 (Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-bu ...)
-	TODO: check
+	NOT-FOR-US: Craft CMS or plugin for Craft CMS
 CVE-2026-73591 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-73589 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-73588 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-73587 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-73586 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-73192 (An improper neutralization of input during web page generation ('Cross ...)
 	TODO: check
 CVE-2026-71465 (RunAdHocCommand.build_args() appends limit as bare               posit ...)
@@ -677,31 +677,31 @@ CVE-2026-71459 (JobJobEventsChildrenSummary view has no model/parent_model.
 CVE-2026-71458 (URLModificationMiddleware resolves named-URL lookups               aga ...)
 	TODO: check
 CVE-2026-71178 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-71177 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-70125 (Microsoft Outlook Remote Code Execution Vulnerability)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-6935 (IBM Concert 1.0.0 through 3.0.0 invokes operating system commands with ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-6928 (IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-6925 (IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to trave ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-6794 (IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that e ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-6730 (IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, ca ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-6721 (IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attac ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-6718 (IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access contr ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-6669 (Missing upper bound on the key derivation iteration count accepted dur ...)
 	TODO: check
 CVE-2026-6668 (Integer overflow in the packet buffer growth logic in PgBouncer throug ...)
 	TODO: check
 CVE-2026-6327 (IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to in ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-68492 (An untrusted search path vulnerability in Plesk from 18.0.34 before 18 ...)
 	TODO: check
 CVE-2026-68490 (Incorrect permission assignment allows local users to obtain sensitive ...)
@@ -775,7 +775,7 @@ CVE-2026-61814 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's Async
 CVE-2026-61695 (Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, an ...)
 	TODO: check
 CVE-2026-61413 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
-	TODO: check
+	NOT-FOR-US: Dell / EMC
 CVE-2026-5696 (Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability  ...)
 	TODO: check
 CVE-2026-5695 (Arbitrary file upload vulnerability due to a lack of proper validation ...)
@@ -807,65 +807,65 @@ CVE-2026-53968
 CVE-2026-52744 (GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the int ...)
 	TODO: check
 CVE-2026-50228 (An unauthenticated local attacker can connect to the Electron DevTools ...)
-	TODO: check
+	NOT-FOR-US: Acer
 CVE-2026-50227 (An unauthenticated local attacker can connect to the MQTT broker over  ...)
-	TODO: check
+	NOT-FOR-US: Acer
 CVE-2026-4921 (IBM Guardium Data Protection 12.2 could allow an administrative user t ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-42801 (NULL pointer dereference vulnerability in ASR Crane\uff0cFalcon on Lin ...)
-	TODO: check
+	NOT-FOR-US: ASR Microelectronics
 CVE-2026-3626 (IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtai ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-31377 (An Improper Authentication vulnerability in the Apache Doris Frontend  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-19888 (Missing validation of a mandatory attribute in the SCRAM client-final- ...)
 	TODO: check
 CVE-2026-19599 (ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were v ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-19267 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulner ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-19179 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-19125 (The EthPress \u2013 Web3 Login plugin for WordPress is vulnerable to A ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-19087 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18944
 	REJECTED
 CVE-2026-18875 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulner ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18872 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulner ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18505 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulner ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18490 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulner ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18467 (The Paytium: Mollie payment forms & donations plugin for WordPress is  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-18185 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18184 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18181 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18180 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18179 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-18177 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift could all ...)
-	TODO: check
+	NOT-FOR-US: IBM
 CVE-2026-15358 (ZohoCorp ManageEngine OpManager and Network Configuration Manager vers ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-15027 (CGServiSign developed by Changing has a OS Command Injection vulnerabi ...)
 	TODO: check
 CVE-2026-14913 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.66 ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-14780 (A vulnerability exists in the PaperCut NG/MF platform's device-scripti ...)
 	TODO: check
 CVE-2026-12974 (A Security Policy Bypass vulnerability exists in Forcepoint Security E ...)
-	TODO: check
+	NOT-FOR-US: Forcepoint
 CVE-2026-12370 (ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configu ...)
-	TODO: check
+	NOT-FOR-US: Zoho
 CVE-2026-11744 (An input validation vulnerability exists in the PaperCut Hive embedded ...)
 	TODO: check
 CVE-2025-63564 (SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through  ...)
@@ -2453,7 +2453,7 @@ CVE-2026-74849 (Zohocorp ManageEngine ADSelfService Plus versions before build 7
 CVE-2026-73369 (Adobe Campaign Classic (ACC) is affected by an Improper Control of Gen ...)
 	NOT-FOR-US: Adobe
 CVE-2026-70410 (Use of Externally-Controlled Input to Select Classes or Code ('Unsafe  ...)
-	TODO: check
+	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-6922 (The WP Table Builder \u2013 Drag & Drop Table Builder plugin for WordP ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-68956 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
@@ -3170,7 +3170,7 @@ CVE-2026-17051 (The Intel SEDI IPM (inter-processor mailbox) driver in drivers/i
 CVE-2026-17050 (The experimental USB host stack allocates a per-device configuration-d ...)
 	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-16652 (Temporal Server did not bound the work performed while searching for a ...)
-	TODO: check
+	NOT-FOR-US: Temporal Technologies
 CVE-2026-16651 (temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNex ...)
 	NOT-FOR-US: temporalio/sqlparser
 CVE-2026-15890 (The default AEAD nonce provider for the PSA Internal Trusted Storage t ...)
@@ -63127,7 +63127,7 @@ CVE-2026-32327 (A bug in APR-util version 1.6.3 (and earlier) allows a stack rec
 	NOTE: https://lists.apache.org/thread/hq27vj8yfno9tkwv0fpj6jksfzgxvth1
 	NOTE: Fixed by: https://github.com/apache/apr-util/commit/414e12e427c89f135d8ee66ab1203feffd3e2bd8 (1.6.4-rc1-candidate)
 CVE-2026-28183 (Incorrect Privilege Assignment vulnerability in PublishPress PublishPr ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28180 (Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pa ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-28179 (Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versio ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29435e1922c30de49164cebb0ca14b93d48e42ed

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/29435e1922c30de49164cebb0ca14b93d48e42ed
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/8cae6a86/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list