[Git][security-tracker-team/security-tracker][master] NFUs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 11:13:01 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
514bd567 by Moritz Muehlenhoff at 2026-09-24T12:12:11+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -709,21 +709,21 @@ CVE-2026-73586 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior
CVE-2026-73192 (An improper neutralization of input during web page generation ('Cross ...)
TODO: check
CVE-2026-71465 (RunAdHocCommand.build_args() appends limit as bare posit ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-71464 (LaunchConfigurationBaseSerializer.scm_branch has no vali ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-71463 (Notification template Jinja AST whitelist only inspects ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-71462 (StringListPathField.to_internal_value() calls os.path.ex ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-71461 (HostList.list() catches bare Exception and returns str(e) ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-71460 (/api/v2/config/ is protected only by IsAuthenticated. li ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-71459 (JobJobEventsChildrenSummary view has no model/parent_model. ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-71458 (URLModificationMiddleware resolves named-URL lookups aga ...)
- TODO: check
+ NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-71178 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
NOT-FOR-US: Dell / EMC
CVE-2026-71177 (Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5. ...)
@@ -751,9 +751,9 @@ CVE-2026-6668 (Integer overflow in the packet buffer growth logic in PgBouncer t
CVE-2026-6327 (IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to in ...)
NOT-FOR-US: IBM
CVE-2026-68492 (An untrusted search path vulnerability in Plesk from 18.0.34 before 18 ...)
- TODO: check
+ NOT-FOR-US: Plesk
CVE-2026-68490 (Incorrect permission assignment allows local users to obtain sensitive ...)
- TODO: check
+ NOT-FOR-US: cPanel
CVE-2026-67405 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
TODO: check
CVE-2026-67404 (RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...)
@@ -905,7 +905,7 @@ CVE-2026-18177 (IBM Financial Transaction Manager (FTM) for RedHat OpenShift cou
CVE-2026-15358 (ZohoCorp ManageEngine OpManager and Network Configuration Manager vers ...)
NOT-FOR-US: Zoho
CVE-2026-15027 (CGServiSign developed by Changing has a OS Command Injection vulnerabi ...)
- TODO: check
+ NOT-FOR-US: CGServiSign
CVE-2026-14913 (ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.66 ...)
NOT-FOR-US: Zoho
CVE-2026-14780 (A vulnerability exists in the PaperCut NG/MF platform's device-scripti ...)
@@ -917,7 +917,7 @@ CVE-2026-12370 (ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network C
CVE-2026-11744 (An input validation vulnerability exists in the PaperCut Hive embedded ...)
NOT-FOR-US: PaperCut
CVE-2025-63564 (SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through ...)
- TODO: check
+ NOT-FOR-US: Moodle plugin
CVE-2026-87022 (Improper handling of length parameter inconsistency vulnerability in A ...)
- tomcat11 <unfixed> (bug #1148824)
- tomcat10 10.1.60-1
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/514bd5675758e214fd3db3b9e8d404321331495f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/514bd5675758e214fd3db3b9e8d404321331495f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/89fdd883/attachment.htm>
More information about the debian-security-tracker-commits
mailing list