[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 10:36:30 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
206b23dc by Moritz Muehlenhoff at 2026-09-24T11:36:08+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,15 @@
+CVE-2026-84680
+ NOT-FOR-US: Red Hat Ansible Automation Platform
+CVE-2026-84679
+ NOT-FOR-US: Red Hat Ansible Automation Platform
+CVE-2026-84678
+ NOT-FOR-US: Red Hat Ansible Automation Platform
+CVE-2026-84644
+ NOT-FOR-US: Red Hat Ansible Automation Platform
+CVE-2026-84643
+ NOT-FOR-US: Red Hat Ansible Automation Platform
+CVE-2026-84638
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-76654
- kubernetes <not-affected> (Windows-specific)
NOTE: https://groups.google.com/g/kubernetes-announce/c/ZN4CNe2li2w
@@ -488,11 +500,11 @@ CVE-2026-88830 (A unit confusion in BusyBox TLS Montgomery reduction buffer allo
CVE-2026-87978 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does not ver ...)
NOT-FOR-US: WordPress plugin
CVE-2026-87900 (Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier a ...)
- TODO: check
+ NOT-FOR-US: cPanel
CVE-2026-87899 (Execution with unnecessary privileges in cPanel allows remote authenti ...)
- TODO: check
+ NOT-FOR-US: cPanel
CVE-2026-87898 (OS command injection in Plesk allows remote authenticated users to exe ...)
- TODO: check
+ NOT-FOR-US: Plesk
CVE-2026-87848 (The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have a ...)
NOT-FOR-US: WordPress plugin
CVE-2026-87739 (An improper authentication vulnerability in PaperCut MF/NG allows an u ...)
@@ -532,13 +544,13 @@ CVE-2026-86601 (The WP Recipe Maker WordPress plugin before 10.8.2 does not remo
CVE-2026-86583 (The Import and export users and customers plugin for WordPress is vuln ...)
NOT-FOR-US: WordPress plugin
CVE-2026-86065 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
- TODO: check
+ NOT-FOR-US: Klever-Go
CVE-2026-86064 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
- TODO: check
+ NOT-FOR-US: Klever-Go
CVE-2026-85724 (Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when patt ...)
TODO: check
CVE-2026-85475 (A flaw was found in the Ansible Automation Platform automation control ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84791 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.71 ...)
NOT-FOR-US: Zoho
CVE-2026-84789 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.71 ...)
@@ -588,13 +600,13 @@ CVE-2026-82850 (The Masteriyo LMS WordPress plugin before 3.4.2 does not restri
CVE-2026-82849 (The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that ...)
NOT-FOR-US: WordPress plugin
CVE-2026-82409 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
- TODO: check
+ NOT-FOR-US: Klever-Go
CVE-2026-82407 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
- TODO: check
+ NOT-FOR-US: Klever-Go
CVE-2026-82406 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
- TODO: check
+ NOT-FOR-US: Klever-Go
CVE-2026-82405 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
- TODO: check
+ NOT-FOR-US: Klever-Go
CVE-2026-82370 (Unauthenticated remote command injection in the Brocade SANnav orchest ...)
NOT-FOR-US: Brocade
CVE-2026-82369 (Insufficient input sanitization of shell metacharacters in the Brocade ...)
@@ -602,7 +614,7 @@ CVE-2026-82369 (Insufficient input sanitization of shell metacharacters in the B
CVE-2026-82368 (Insecure access controls on internal service ports in Brocade SANnav v ...)
NOT-FOR-US: Brocade
CVE-2026-82356 (Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair af ...)
- TODO: check
+ NOT-FOR-US: Imprivata EAM
CVE-2026-82195 (The 10Web Booster WordPress plugin before 2.34.0 does not restrict ac ...)
NOT-FOR-US: WordPress plugin
CVE-2026-82077 (An improper limitation of a pathname to a restricted directory (path t ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/206b23dc468effde268e23d8573448f1eb4047b1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/206b23dc468effde268e23d8573448f1eb4047b1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/5e318bde/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list