[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 24 10:36:30 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
206b23dc by Moritz Muehlenhoff at 2026-09-24T11:36:08+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,15 @@
+CVE-2026-84680
+	NOT-FOR-US: Red Hat Ansible Automation Platform
+CVE-2026-84679
+	NOT-FOR-US: Red Hat Ansible Automation Platform
+CVE-2026-84678
+	NOT-FOR-US: Red Hat Ansible Automation Platform
+CVE-2026-84644
+	NOT-FOR-US: Red Hat Ansible Automation Platform
+CVE-2026-84643
+	NOT-FOR-US: Red Hat Ansible Automation Platform
+CVE-2026-84638
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-76654
 	- kubernetes <not-affected> (Windows-specific)
 	NOTE: https://groups.google.com/g/kubernetes-announce/c/ZN4CNe2li2w
@@ -488,11 +500,11 @@ CVE-2026-88830 (A unit confusion in BusyBox TLS Montgomery reduction buffer allo
 CVE-2026-87978 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does not ver ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-87900 (Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier a ...)
-	TODO: check
+	NOT-FOR-US: cPanel
 CVE-2026-87899 (Execution with unnecessary privileges in cPanel allows remote authenti ...)
-	TODO: check
+	NOT-FOR-US: cPanel
 CVE-2026-87898 (OS command injection in Plesk allows remote authenticated users to exe ...)
-	TODO: check
+	NOT-FOR-US: Plesk
 CVE-2026-87848 (The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have a ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-87739 (An improper authentication vulnerability in PaperCut MF/NG allows an u ...)
@@ -532,13 +544,13 @@ CVE-2026-86601 (The WP Recipe Maker WordPress plugin before 10.8.2 does not remo
 CVE-2026-86583 (The Import and export users and customers plugin for WordPress is vuln ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-86065 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
-	TODO: check
+	NOT-FOR-US: Klever-Go
 CVE-2026-86064 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
-	TODO: check
+	NOT-FOR-US: Klever-Go
 CVE-2026-85724 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when patt ...)
 	TODO: check
 CVE-2026-85475 (A flaw was found in the Ansible Automation Platform automation control ...)
-	TODO: check
+	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-84791 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.71 ...)
 	NOT-FOR-US: Zoho
 CVE-2026-84789 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.71 ...)
@@ -588,13 +600,13 @@ CVE-2026-82850 (The Masteriyo LMS  WordPress plugin before 3.4.2 does not restri
 CVE-2026-82849 (The Masteriyo LMS  WordPress plugin before 3.4.2 does not verify that  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-82409 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
-	TODO: check
+	NOT-FOR-US: Klever-Go
 CVE-2026-82407 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
-	TODO: check
+	NOT-FOR-US: Klever-Go
 CVE-2026-82406 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
-	TODO: check
+	NOT-FOR-US: Klever-Go
 CVE-2026-82405 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
-	TODO: check
+	NOT-FOR-US: Klever-Go
 CVE-2026-82370 (Unauthenticated remote command injection in the Brocade SANnav orchest ...)
 	NOT-FOR-US: Brocade
 CVE-2026-82369 (Insufficient input sanitization of shell metacharacters in the Brocade ...)
@@ -602,7 +614,7 @@ CVE-2026-82369 (Insufficient input sanitization of shell metacharacters in the B
 CVE-2026-82368 (Insecure access controls on internal service ports in Brocade SANnav v ...)
 	NOT-FOR-US: Brocade
 CVE-2026-82356 (Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair af ...)
-	TODO: check
+	NOT-FOR-US: Imprivata EAM
 CVE-2026-82195 (The 10Web Booster  WordPress plugin before 2.34.0 does not restrict ac ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-82077 (An improper limitation of a pathname to a restricted directory (path t ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/206b23dc468effde268e23d8573448f1eb4047b1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/206b23dc468effde268e23d8573448f1eb4047b1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/5e318bde/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list