Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a0b09dba by security tracker role at 2026-09-16T19:15:19+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -57,7 +57,7 @@ CVE-2026-92467 (zlt2000 microservices-platform through 6.0.0 
contains an unverif
 CVE-2026-92466 (zlt2000 microservices-platform through 6.0.0 contains a 
missing author ...)
        TODO: check
 CVE-2026-92465 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin or theme
 CVE-2026-92463 (yshop-crm through 2.1.3 contains an authorization failure in 
the GET / ...)
        TODO: check
 CVE-2026-92462 (yshop-crm through 2.1.3 fails to enforce authorization checks 
on the C ...)
@@ -85,9 +85,9 @@ CVE-2026-92416 (A vulnerability has been found in Open5GS up 
to 2.8.0. Affected
 CVE-2026-92413 (A flaw has been found in Artifex MuPDF up to 
b6d17493700c621c0e7003698 ...)
        TODO: check
 CVE-2026-92406 (A vulnerability was detected in SourceCodester Inventory and 
Monitorin ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-92405 (A security vulnerability has been detected in SourceCodester 
Inventory ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-92402 (A security flaw has been discovered in ChangeWeDer crm up to 
c07bd4c97 ...)
        TODO: check
 CVE-2026-92401 (A vulnerability was identified in ChangeWeDer crm up to 
c07bd4c9714152 ...)
@@ -101,7 +101,7 @@ CVE-2026-92397 (A vulnerability has been found in Ruijie 
RG-EW3000GX EW_3.0(1)B1
 CVE-2026-92395 (@fastify/proxy-addr is a Fastify plugin that determines a 
request's cl ...)
        TODO: check
 CVE-2026-92385 (A vulnerability has been found in SourceCodester Online Food 
Ordering  ...)
-       TODO: check
+       NOT-FOR-US: SourceCodester
 CVE-2026-92383 (A security vulnerability has been detected in PbootCMS up to 
3.2.24. T ...)
        TODO: check
 CVE-2026-92381 (A weakness has been identified in PbootCMS up to 3.2.22. This 
affects  ...)
@@ -109,11 +109,11 @@ CVE-2026-92381 (A weakness has been identified in 
PbootCMS up to 3.2.22. This af
 CVE-2026-92380 (A flaw has been found in WuzhiCMS up to 4.1.0. The impacted 
element is ...)
        TODO: check
 CVE-2026-92366 (A vulnerability was determined in code-projects Matrimonial 
System 1.0 ...)
-       TODO: check
+       NOT-FOR-US: code-projects
 CVE-2026-92365 (A vulnerability was found in vllm-project vllm up to 0.29.0. 
Affected  ...)
        TODO: check
 CVE-2026-92364 (A vulnerability has been found in itsourcecode Leave 
Management System ...)
-       TODO: check
+       NOT-FOR-US: itsourcecode System
 CVE-2026-92363 (A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is 
an unkn ...)
        TODO: check
 CVE-2026-92362 (A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This 
impacts ...)
@@ -131,13 +131,13 @@ CVE-2026-92357 (A vulnerability was identified in 
a2ui-project a2ui 0.8/0.9/1.0.
 CVE-2026-92356 (A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. 
This is ...)
        TODO: check
 CVE-2026-92355 (In affected versions of Octopus Server, a user with permission 
to modi ...)
-       TODO: check
+       NOT-FOR-US: Octopus Deploy
 CVE-2026-92299 (@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() 
via cont ...)
        TODO: check
 CVE-2026-92298 (EspoCRM through 10.0.8 uses PHP's rand() function to generate 
tokens f ...)
        TODO: check
 CVE-2026-92259 (Integer overflow or wraparound vulnerability in Samsung 
Opensource Esc ...)
-       TODO: check
+       NOT-FOR-US: Samsung
 CVE-2026-92257 (Netcore NR255-V version 1.5.130703 contains a stored 
cross-site script ...)
        TODO: check
 CVE-2026-92256 (NR255-V version 1.5.130703 contains a sensitive information 
disclosure ...)
@@ -147,7 +147,7 @@ CVE-2026-92255 (Netcore NR255-V version 1.5.130703 contains 
an out-of-bounds rea
 CVE-2026-92247 (A security vulnerability has been detected in synaptikcms 
synaptik-cms ...)
        TODO: check
 CVE-2026-92237 (Insertion of sensitive information into log file in the slow 
query log ...)
-       TODO: check
+       NOT-FOR-US: Devolutions
 CVE-2026-92234 (QloApps through 1.7.0 reflects unescaped child feature names 
into back ...)
        TODO: check
 CVE-2026-92221 (A vulnerability was determined in gedelumbung 
HospitalManagement up to ...)
@@ -167,45 +167,45 @@ CVE-2026-92213 (A vulnerability was detected in 
a2ui-project a2ui up to 0.10.6.
 CVE-2026-92184 (A security flaw has been discovered in ag-ui-protocol ag-ui 
0.3.0. Aff ...)
        TODO: check
 CVE-2026-92141 (Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does 
not rest ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92140 (Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not 
escape th ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92139 (Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and 
earlier trust ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92138 (The OAuth authorization endpoint in Jenkins Bitbucket Server 
Integrati ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92137 (Jenkins Robot Framework Plugin 6.2.2 and earlier does not 
check that t ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92136 (Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does 
not escap ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92135 (Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does 
not vali ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92134 (Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier 
does not ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92133 (Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches 
the Git ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92132 (Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier 
requests b ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92131 (Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d 
and earli ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92130 (Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and 
earlier do ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92129 (Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and 
earlier does  ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92128 (Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and 
earlier downl ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92127 (Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and 
earlier autom ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92126 (Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and 
earlier does  ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92125 (Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and 
earlier does  ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92124 (Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and 
earlier check ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92123 (Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and 
earlier does  ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92122 (Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and 
earlier does  ...)
-       TODO: check
+       NOT-FOR-US: Jenkins (core or plugin)
 CVE-2026-92114 (A vulnerability was identified in a2ui-project a2ui up to 
0.10.6. Affe ...)
        TODO: check
 CVE-2026-92091 (A flaw was found in jwcrypto. The JWK.import_key() function 
validates  ...)
@@ -219,45 +219,45 @@ CVE-2026-91939 (Cotonti 1.0.0 Comments plugin passes the 
ci GET parameter to uns
 CVE-2026-91843 (A stack overflow during the unauthenticated login process may 
allow an ...)
        TODO: check
 CVE-2026-91106 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-91105 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-91104 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-91103 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-91102 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-91101 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-91100 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-91099 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-91098 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-91097 (HP has identified and remediated multiple externally reported 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: HP
 CVE-2026-90999 (Sentry Seer is vulnerable to a multi-stage trust-boundary 
violation th ...)
        TODO: check
 CVE-2026-90971 (Server-Side Request Forgery (SSRF) in the VMware 
synchronization featu ...)
-       TODO: check
+       NOT-FOR-US: Devolutions
 CVE-2026-90969 (Improper access control in the vault entry listing feature 
inDevolutio ...)
-       TODO: check
+       NOT-FOR-US: Devolutions
 CVE-2026-8462 (SQL injection in ClickHouse-backed meter definitions in 
OpenMeter Open ...)
        TODO: check
 CVE-2026-8030 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-89328 (The FluentBoards  WordPress plugin before 2.0.15 does not 
properly ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-89327 (The FluentBoards  WordPress plugin before 2.0.15 does not 
verify that  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-89207 (A vulnerability has been identified in WTV676-HB6035 Web 
Interface (Al ...)
-       TODO: check
+       NOT-FOR-US: Siemens
 CVE-2026-89186 (Use of Cache Containing Sensitive Information in ZenHive mpp 
allows a  ...)
        TODO: check
 CVE-2026-89063 (The Online Scheduling and Appointment Booking System \u2013 
Bookly plu ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-89040 (Tencent Mass Service Engine in Cluster (MSEC) allows a remote, 
unauthe ...)
        TODO: check
 CVE-2026-89031 (Adenion Blog2Social plugin for WordPress before 9.1.0 allows 
low-privi ...)
@@ -267,7 +267,7 @@ CVE-2026-89030 (Adenion Blog2Social plugin for WordPress 
before 9.1.0 exposes th
 CVE-2026-89029 (Adenion Blog2Social plugin for WordPress before 9.1.0 allows 
low-privi ...)
        TODO: check
 CVE-2026-89028 (MikroTik RouterOS before 7.24 contains a heap memory 
corruption vulner ...)
-       TODO: check
+       NOT-FOR-US: MikroTik
 CVE-2026-89027 (miniOrange JWT Authentication for WP REST APIs plugin for 
WordPress be ...)
        TODO: check
 CVE-2026-88976 (Plate is a rich-text editor with AI and shadcn/ui. Prior to 
53.3.11, a ...)
@@ -277,7 +277,7 @@ CVE-2026-88975 (Http4s is a Scala interface for HTTP 
services. Prior to 0.23.37
 CVE-2026-88922 (The go-getter library up to versions 1.8.8 and 2.2.3 is 
vulnerable to  ...)
        TODO: check
 CVE-2026-88910 (The kboard WordPress plugin before 6.7 does not verify 
ownership or co ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-88817 (An authenticated, non-guest user of Curiosity Workspace could 
enroll t ...)
        TODO: check
 CVE-2026-88743 (Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site 
scripting ( ...)
@@ -295,19 +295,19 @@ CVE-2026-88065 (`tts-be` is a backend for a timetable 
selector that aims to help
 CVE-2026-88064 (Backstage is an open framework for building developer portals. 
Prior t ...)
        TODO: check
 CVE-2026-87959 (The WPBot  WordPress plugin before 8.7.6 does not perform a 
capability ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87907 (The Rox Appointment Booking  WordPress plugin before 1.2.8 
does not pe ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87896 (The Rox Appointment Booking  WordPress plugin before 1.2.8 
does not pe ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87860 (The Subscriptions for WooCommerce WordPress plugin before 
2.0.3 does n ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87854 (The Subscriptions for WooCommerce WordPress plugin before 
2.0.3 does n ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87828 (The Seraphinite Accelerator WordPress plugin before 2.29.24 
does not p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-87289 (Vulnerability in the Helidon product of Oracle Fusion 
Middleware (comp ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87288 (Vulnerability in the Oracle GraalVM product of Oracle Java SE 
(compone ...)
        TODO: check
 CVE-2026-87287 (Vulnerability in the Oracle GraalVM product of Oracle Java SE 
(compone ...)
@@ -353,207 +353,207 @@ CVE-2026-87268 (Vulnerability in the Oracle VM 
VirtualBox product of Oracle Virt
 CVE-2026-87267 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
        TODO: check
 CVE-2026-87266 (Vulnerability in the Oracle Agile PLM product of Oracle Supply 
Chain ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87265 (Vulnerability in the Oracle Purchasing product of Oracle 
E-Business Su ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87264 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87262 (Vulnerability in the Oracle Agile Engineering Data Management 
product  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87261 (Vulnerability in the Oracle Agile Engineering Data Management 
product  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87260 (Vulnerability in the Oracle Agile Engineering Data Management 
product  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87259 (Vulnerability in the Oracle Agile Engineering Data Management 
product  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87258 (Vulnerability in the Oracle Agile PLM product of Oracle Supply 
Chain ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87257 (Vulnerability in the Oracle Agile PLM product of Oracle Supply 
Chain ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87256 (Vulnerability in the Oracle Agile PLM product of Oracle Supply 
Chain ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87254 (Vulnerability in the Oracle Agile PLM product of Oracle Supply 
Chain ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87253 (Vulnerability in the Oracle Agile PLM product of Oracle Supply 
Chain ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87252 (Vulnerability in the Oracle Agile PLM product of Oracle Supply 
Chain ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87250 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87249 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87248 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87247 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87246 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87245 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87244 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87243 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87242 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87241 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87240 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87239 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87238 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87237 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87236 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87235 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87234 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87233 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87232 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87231 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87230 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87229 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87228 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87227 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87226 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87225 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87224 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87223 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87222 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87221 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87220 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87219 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87218 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87217 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87216 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87215 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87214 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87213 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87212 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87211 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87210 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87209 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87208 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87207 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87206 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87205 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87204 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87203 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87202 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87201 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87200 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87199 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87198 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87197 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87196 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87195 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87194 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87193 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87192 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87191 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87190 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87189 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87188 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87187 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87186 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87185 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87184 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87183 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87182 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87181 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87180 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87179 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87178 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87177 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87176 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87175 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87174 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87173 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87172 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87171 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87170 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87169 (Vulnerability in the Oracle Contract Lifecycle Management for 
Public S ...)
        TODO: check
 CVE-2026-87168 (Vulnerability in the Oracle Purchasing product of Oracle 
E-Business Su ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87167 (Vulnerability in the Oracle Purchasing product of Oracle 
E-Business Su ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87166 (Vulnerability in the Oracle Purchasing product of Oracle 
E-Business Su ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87165 (Vulnerability in the Oracle Contract Lifecycle Management for 
Public S ...)
        TODO: check
 CVE-2026-87164 (Vulnerability in the Oracle Banking Branch product of Oracle 
Financial ...)
        TODO: check
 CVE-2026-87163 (Vulnerability in the Oracle Purchasing product of Oracle 
E-Business Su ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87162 (Vulnerability in the Oracle Contract Lifecycle Management for 
Public S ...)
        TODO: check
 CVE-2026-87161 (Vulnerability in the Oracle HRMS (India) product of Oracle 
E-Business  ...)
@@ -563,17 +563,17 @@ CVE-2026-87160 (Vulnerability in the Oracle HRMS (India) 
product of Oracle E-Bus
 CVE-2026-87159 (Vulnerability in the Oracle HRMS (India) product of Oracle 
E-Business  ...)
        TODO: check
 CVE-2026-87158 (Vulnerability in the Oracle Order Management product of Oracle 
E-Busin ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87157 (Vulnerability in the Oracle Order Management product of Oracle 
E-Busin ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87156 (Vulnerability in the Oracle Product Hub product of Oracle 
E-Business S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87155 (Vulnerability in the Oracle Product Hub product of Oracle 
E-Business S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87154 (Vulnerability in the Oracle Product Hub product of Oracle 
E-Business S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87153 (Vulnerability in the Oracle Product Hub product of Oracle 
E-Business S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87152 (Vulnerability in the Oracle Installed Base product of Oracle 
E-Busines ...)
        TODO: check
 CVE-2026-87151 (Vulnerability in the Oracle Bills of Material product of 
Oracle E-Busi ...)
@@ -583,111 +583,111 @@ CVE-2026-87150 (Vulnerability in the Oracle Bills of 
Material product of Oracle
 CVE-2026-87149 (Vulnerability in the Oracle Contract Lifecycle Management for 
Public S ...)
        TODO: check
 CVE-2026-87148 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87147 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87146 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87145 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87144 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87143 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87142 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87141 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87140 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87139 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87138 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87137 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87136 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87135 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87134 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87133 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87132 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87131 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87130 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87129 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87128 (Vulnerability in the Oracle Hyperion Data Relationship 
Management prod ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87127 (Vulnerability in the Oracle Purchasing product of Oracle 
E-Business Su ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87126 (Vulnerability in the Oracle Report Manager product of Oracle 
E-Busines ...)
        TODO: check
 CVE-2026-87125 (Vulnerability in the Oracle Financials for Asia/Pacific 
product of Ora ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87124 (Vulnerability in the Oracle iRecruitment product of Oracle 
E-Business  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-87031 (n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation 
endpoin ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-87028 (Concrete CMS 9 through 9.5.3 did not confirm that a board 
InstanceItem ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-86823 (The Newsletter  WordPress plugin before 9.3.7 does not 
validate the de ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86792 (Apache Airflow Apache Kafka provider versions 1.15.0 before 
2.0.0 reso ...)
        TODO: check
 CVE-2026-86784 (The Visualizer  WordPress plugin before 4.0.8 does not 
sanitise and es ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86585 (The lack of signature verification of firmware update packages 
in VEO  ...)
        TODO: check
 CVE-2026-86475 (The Appointment Hour Booking WordPress plugin before 1.5.95 
does not c ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86474 (The lack of TLS certificate validation when downloading 
firmware updat ...)
        TODO: check
 CVE-2026-86466 (Apache Airflow FAB provider: the Authentik OAuth path in the 
FAB auth  ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-86465 (Apache Airflow Akeyless provider: the Akeyless secrets 
backend's team- ...)
        TODO: check
 CVE-2026-86462 (Apache Airflow FAB provider: changing a user's password 
through the Ad ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-86449 (The LearnPress  WordPress plugin before 4.4.7 does not check 
the user' ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86448 (The LearnPress  WordPress plugin before 4.4.7 does not perform 
any aut ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86447 (The LearnPress  WordPress plugin before 4.4.7 does not check 
the user' ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86445 (The LearnPress  WordPress plugin before 4.4.7 does not check 
the user' ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86444 (The LearnPress  WordPress plugin before 4.4.7 does not escape 
a user s ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-86443 (Cleartext storage of sensitive information in the DuoxMe 
application f ...)
        TODO: check
 CVE-2026-86359 (Dell Repository Manager, versions prior to 3.5.2, contains an 
Incorrec ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-86358 (Dell Update Package Framework, versions prior to 26.07.03, 
contains a  ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-86341 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-86338 (Ash field_policies are documented to protect against 
filter-based info ...)
        TODO: check
 CVE-2026-86109 (The VeloCloud Edge software update workflow may accept update 
bundles  ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-86108 (Insufficient validation of inputs supplied through affected 
VeloCloud  ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-86107 (The VeloCloud Edge and Gateway exhibit an out-of-bounds write 
vulnerab ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-86106 (An unauthenticated actor with network access to the private HA 
interco ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-86043 (Skipper is an HTTP router and reverse proxy for service 
composition. P ...)
        TODO: check
 CVE-2026-86003 (CoreDNS is a DNS server written in Go. Prior to 1.14.7, the 
DNS-over-H ...)
        TODO: check
 CVE-2026-85893 (Use after free in Microsoft Edge (Chromium-based) allows an 
unauthoriz ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-85756 (SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 
2026.0.0, S ...)
        TODO: check
 CVE-2026-85732 (oras-go is a Go library for managing OCI artifacts. Prior to 
2.6.2, th ...)
@@ -695,25 +695,25 @@ CVE-2026-85732 (oras-go is a Go library for managing OCI 
artifacts. Prior to 2.6
 CVE-2026-85731 (oras-go is a Go library for managing OCI artifacts. Prior to 
2.6.2, co ...)
        TODO: check
 CVE-2026-85641 (The Formidable Forms  WordPress plugin before 6.35 does not 
restrict w ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-85628 (Transmission of the home Wi-Fi credentials without encryption 
during t ...)
        TODO: check
 CVE-2026-85572 (The Tutor LMS  WordPress plugin before 4.0.8 does not check 
that a use ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-85569 (The Tutor LMS  WordPress plugin before 4.0.8 does not 
correctly determ ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-85530 (The GiveWP  WordPress plugin before 4.16.8.1 does not 
consistently nor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-85387 (Concrete CMS before 9.5.4 re-authorized OAuth REST API 
requests from t ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-85386 (Concrete CMS before 9.5.4 did not sanitize XML and XSLT 
documents uplo ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-85385 (Concrete CMS below 9.5.4 did not validate the user timezone 
value (uTi ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-85349 (The FluentBoards  WordPress plugin before 2.0.15 does not 
properly ver ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-85131 (The WPLP Cookie Consent  WordPress plugin before 4.4.4 does 
not perfor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-85104 (In Sooma 2GEN brain stimulator, an attacker within Bluetooth 
range can ...)
        TODO: check
 CVE-2026-84997 (react/http is an event-driven, streaming HTTP client and 
server implem ...)
@@ -721,11 +721,11 @@ CVE-2026-84997 (react/http is an event-driven, streaming 
HTTP client and server
 CVE-2026-84993 (MikroORM is a TypeScript ORM for Node.js based on Data Mapper, 
Unit of ...)
        TODO: check
 CVE-2026-84907 (The Eventin  WordPress plugin before 4.1.24 does not properly 
authoris ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84906 (The Eventin WordPress plugin before 4.1.24 does not verify 
that a comp ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84905 (The Eventin  WordPress plugin before 4.1.24 does not verify a 
user's c ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84860 (ScadaLTS 2.8.1-release-candidate build 0 is affected by 
anAuthorizatio ...)
        TODO: check
 CVE-2026-84859 (ScadaLTS 2.8.1-release-candidate build 0 is affected by 
anAuthenticate ...)
@@ -733,9 +733,9 @@ CVE-2026-84859 (ScadaLTS 2.8.1-release-candidate build 0 is 
affected by anAuthen
 CVE-2026-84858 (ScadaLTS 2.8.1-release-candidate build 0 is affected by 
anAuthenticate ...)
        TODO: check
 CVE-2026-84850 (Improper certificate validation in the shared HTTP client used 
by sync ...)
-       TODO: check
+       NOT-FOR-US: Devolutions
 CVE-2026-84829 (The Optimole  WordPress plugin before 4.2.12 does not properly 
escape  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84501 (An unauthenticated attacker can inject arbitrary fake log 
lines into A ...)
        TODO: check
 CVE-2026-84439 (When audit logging is enabled (zookeeper.audit.enable=true), 
an unauth ...)
@@ -743,25 +743,25 @@ CVE-2026-84439 (When audit logging is enabled 
(zookeeper.audit.enable=true), an
 CVE-2026-84408 (QND contains an improper access control vulnerability in a 
named pipe, ...)
        TODO: check
 CVE-2026-84397 (Adobe Experience Manager is affected by a stored Cross-Site 
Scripting  ...)
-       TODO: check
+       NOT-FOR-US: Adobe
 CVE-2026-84088 (The Xpro Addons \u2014 140+ Widgets for Elementor WordPress 
plugin bef ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-84048 (Joomla Extension - joomgalleryfriends.net - Unauthenticated 
arbitrary  ...)
-       TODO: check
+       NOT-FOR-US: Joomla
 CVE-2026-83491 (Vulnerability in the Oracle iRecruitment product of Oracle 
E-Business  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83490 (Vulnerability in the Oracle iRecruitment product of Oracle 
E-Business  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83489 (Vulnerability in the Oracle Banking Origination product of 
Oracle Fina ...)
        TODO: check
 CVE-2026-83488 (Vulnerability in the Helidon product of Oracle Fusion 
Middleware (comp ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83487 (Vulnerability in the Oracle Product Hub product of Oracle 
E-Business S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83486 (Vulnerability in the Oracle Product Hub product of Oracle 
E-Business S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83485 (Vulnerability in the Oracle Product Hub product of Oracle 
E-Business S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83484 (Vulnerability in the Oracle US Federal Human Resources product 
of Orac ...)
        TODO: check
 CVE-2026-83483 (Vulnerability in the Oracle Advanced Benefits product of 
Oracle E-Busi ...)
@@ -771,7 +771,7 @@ CVE-2026-83482 (Vulnerability in the Oracle Contracts 
product of Oracle E-Busine
 CVE-2026-83481 (Vulnerability in the Oracle Contracts product of Oracle 
E-Business Sui ...)
        TODO: check
 CVE-2026-83480 (Vulnerability in the Helidon product of Oracle Fusion 
Middleware (comp ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83479 (Vulnerability in the Oracle Contracts product of Oracle 
E-Business Sui ...)
        TODO: check
 CVE-2026-83477 (Vulnerability in the Oracle Work in Process product of Oracle 
E-Busine ...)
@@ -787,11 +787,11 @@ CVE-2026-83462 (Vulnerability in the Oracle Mobile 
Application Server product of
 CVE-2026-83461 (Vulnerability in the Oracle Mobile Application Server product 
of Oracl ...)
        TODO: check
 CVE-2026-83460 (Vulnerability in the Helidon product of Oracle Fusion 
Middleware (comp ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83459 (Vulnerability in the Helidon product of Oracle Fusion 
Middleware (comp ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83458 (Vulnerability in the Helidon product of Oracle Fusion 
Middleware (comp ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83457 (Vulnerability in the Oracle Demand Signal Repository product 
of Oracle ...)
        TODO: check
 CVE-2026-83456 (Vulnerability in the Oracle Demand Signal Repository product 
of Oracle ...)
@@ -817,19 +817,19 @@ CVE-2026-83447 (Vulnerability in the Oracle Bills of 
Material product of Oracle
 CVE-2026-83446 (Vulnerability in the Oracle Financials Common Modules product 
of Oracl ...)
        TODO: check
 CVE-2026-83445 (Vulnerability in the Oracle Complex Maintenance, Repair and 
Overhaul p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83444 (Vulnerability in the Oracle Product Hub product of Oracle 
E-Business S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83443 (Vulnerability in the Oracle Assets product of Oracle 
E-Business Suite  ...)
        TODO: check
 CVE-2026-83442 (Vulnerability in the Oracle Product Hub product of Oracle 
E-Business S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83441 (Vulnerability in the Oracle Product Hub product of Oracle 
E-Business S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83440 (Vulnerability in the Oracle Product Hub product of Oracle 
E-Business S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83439 (Vulnerability in the Helidon product of Oracle Fusion 
Middleware (comp ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83438 (Vulnerability in the Oracle Engineering product of Oracle 
E-Business S ...)
        TODO: check
 CVE-2026-83437 (Vulnerability in the Oracle Engineering product of Oracle 
E-Business S ...)
@@ -853,13 +853,13 @@ CVE-2026-83429 (Vulnerability in the Oracle Demand Signal 
Repository product of
 CVE-2026-83428 (Vulnerability in the Oracle Demand Signal Repository product 
of Oracle ...)
        TODO: check
 CVE-2026-83425 (Vulnerability in the Oracle Complex Maintenance, Repair and 
Overhaul p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83424 (Vulnerability in the Oracle JDeveloper product of Oracle 
Fusion Middle ...)
        TODO: check
 CVE-2026-83423 (Vulnerability in the Oracle JDeveloper product of Oracle 
Fusion Middle ...)
        TODO: check
 CVE-2026-83422 (Vulnerability in the Oracle Identity Manager product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83420 (Vulnerability in the PeopleSoft Enterprise FIN Engineering 
Brazil prod ...)
        TODO: check
 CVE-2026-83419 (Vulnerability in the Oracle Communications Cloud Native Core 
Security  ...)
@@ -869,23 +869,23 @@ CVE-2026-83418 (Vulnerability in the Oracle 
Communications Cloud Native Core Sec
 CVE-2026-83417 (Vulnerability in the Oracle Communications Cloud Native Core 
Security  ...)
        TODO: check
 CVE-2026-83416 (Vulnerability in the Oracle Coherence product of Oracle Fusion 
Middlew ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83415 (Vulnerability in the Oracle Coherence product of Oracle Fusion 
Middlew ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83414 (Vulnerability in the Oracle Coherence product of Oracle Fusion 
Middlew ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83413 (Vulnerability in the Oracle Coherence product of Oracle Fusion 
Middlew ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83412 (Vulnerability in the Oracle Coherence product of Oracle Fusion 
Middlew ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83411 (Vulnerability in the Oracle Coherence product of Oracle Fusion 
Middlew ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83410 (Vulnerability in the Oracle Coherence product of Oracle Fusion 
Middlew ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83408 (Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM 
product of ...)
        TODO: check
 CVE-2026-83369 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83368 (Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM 
Enterprise ...)
        TODO: check
 CVE-2026-83357 (Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM 
product of ...)
@@ -895,335 +895,335 @@ CVE-2026-83356 (Vulnerability in the Enterprise Command 
Center Framework product
 CVE-2026-83355 (Vulnerability in the Oracle Enterprise Manager for Fusion 
Middleware p ...)
        TODO: check
 CVE-2026-83354 (Vulnerability in the Oracle Coherence product of Oracle Fusion 
Middlew ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83353 (Vulnerability in the Oracle WebCenter Content product of 
Oracle Fusion ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83352 (Vulnerability in the Oracle XML Gateway product of Oracle 
E-Business S ...)
        TODO: check
 CVE-2026-83351 (Vulnerability in the RDBMS component of Oracle Database 
Server.  Suppo ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83350 (Vulnerability in the Oracle Net Services component of Oracle 
Database  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83349 (Vulnerability in the Oracle Net Services component of Oracle 
Database  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83348 (Vulnerability in the RDBMS component of Oracle Database 
Server.  Suppo ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83347 (Vulnerability in the Oracle Net Services component of Oracle 
Database  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83346 (Vulnerability in the Oracle Fusion Middleware Control product 
of Oracl ...)
        TODO: check
 CVE-2026-83345 (Vulnerability in the Oracle XML Gateway product of Oracle 
E-Business S ...)
        TODO: check
 CVE-2026-83344 (Vulnerability in the Oracle Identity Manager Connector product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83343 (Vulnerability in the Oracle Utilities Network Management 
System produc ...)
        TODO: check
 CVE-2026-83342 (Vulnerability in the Oracle Utilities Network Management 
System produc ...)
        TODO: check
 CVE-2026-83341 (Vulnerability in the Oracle Applications Manager product of 
Oracle E-B ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83340 (Vulnerability in the Oracle Identity Manager product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83339 (Vulnerability in the Oracle WebCenter Enterprise Capture 
product of Or ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83338 (Vulnerability in the Oracle Applications Manager product of 
Oracle E-B ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83337 (Vulnerability in the Oracle Middleware Common Libraries and 
Tools prod ...)
        TODO: check
 CVE-2026-83336 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83335 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83334 (Vulnerability in the Oracle Web Services Manager product of 
Oracle Fus ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83333 (Vulnerability in the Oracle Net Services component of Oracle 
Database  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83332 (Vulnerability in the Oracle Applications Framework product of 
Oracle E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83331 (Vulnerability in the Oracle Applications Framework product of 
Oracle E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83330 (Vulnerability in the Helidon product of Oracle Fusion 
Middleware (comp ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83329 (Vulnerability in the Oracle Applications Framework product of 
Oracle E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83328 (Vulnerability in the Oracle Applications Framework product of 
Oracle E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83327 (Vulnerability in the Oracle Applications Framework product of 
Oracle E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83326 (Vulnerability in the Siebel CRM Integration product of Oracle 
Siebel C ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83325 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83324 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83323 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83322 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83321 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83320 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83319 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83318 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83317 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83316 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83315 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83314 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83313 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83312 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83311 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83310 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83309 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83308 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83307 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83306 (Vulnerability in the Oracle JDeveloper product of Oracle 
Fusion Middle ...)
        TODO: check
 CVE-2026-83305 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83304 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83303 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83302 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83301 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83300 (Vulnerability in the Oracle XML Gateway product of Oracle 
E-Business S ...)
        TODO: check
 CVE-2026-83299 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83298 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83297 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83296 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83295 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83294 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83293 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83292 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83291 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83290 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83289 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83288 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83287 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83286 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83285 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83284 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83283 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83282 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83281 (Vulnerability in the Helidon product of Oracle Fusion 
Middleware (comp ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83280 (Vulnerability in the Helidon product of Oracle Fusion 
Middleware (comp ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83279 (Vulnerability in the Oracle Agile PLM MCAD Connector product 
of Oracle ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83278 (Vulnerability in the Helidon product of Oracle Fusion 
Middleware (comp ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83277 (Vulnerability in the Oracle Agile PLM MCAD Connector product 
of Oracle ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83276 (Vulnerability in the Helidon product of Oracle Fusion 
Middleware (comp ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83274 (Vulnerability in the Oracle Agile PLM MCAD Connector product 
of Oracle ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83273 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83272 (Vulnerability in the Oracle Text component of Oracle Database 
Server.  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83271 (Vulnerability in the RDBMS component of Oracle Database 
Server.  Suppo ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83270 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83269 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83268 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83267 (Vulnerability in the Oracle BI Publisher product of Oracle 
Analytics ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83266 (Vulnerability in the Oracle JDeveloper product of Oracle 
Fusion Middle ...)
        TODO: check
 CVE-2026-83265 (Vulnerability in the Oracle Web Services Manager product of 
Oracle Fus ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83264 (Vulnerability in the Oracle Product Lifecycle Analytics 
product of Ora ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83263 (Vulnerability in the Oracle Product Lifecycle Analytics 
product of Ora ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83262 (Vulnerability in the Oracle Product Lifecycle Analytics 
product of Ora ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83261 (Vulnerability in the Oracle Product Lifecycle Analytics 
product of Ora ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83260 (Vulnerability in the Oracle Agile PLM product of Oracle Supply 
Chain ( ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83259 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83258 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83257 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83256 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83255 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83254 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83253 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83252 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83251 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83250 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83249 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83248 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83247 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83246 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83245 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83244 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83243 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83242 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83241 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83240 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83239 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83238 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83237 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83236 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83235 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83234 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83233 (Vulnerability in the Oracle Commerce Guided Search / Oracle 
Commerce E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83232 (Vulnerability in the Oracle Data Integrator product of Oracle 
Fusion M ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83231 (Vulnerability in the Helidon product of Oracle Fusion 
Middleware (comp ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83230 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83229 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83228 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83227 (Vulnerability in the Siebel CRM Integration product of Oracle 
Siebel C ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83226 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83225 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83224 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83223 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83222 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83221 (Vulnerability in the Siebel CRM Integration product of Oracle 
Siebel C ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83220 (Vulnerability in the Siebel CRM Integration product of Oracle 
Siebel C ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83219 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83218 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83217 (Vulnerability in the Siebel CRM End User product of Oracle 
Siebel CRM  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83216 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83215 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83214 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83213 (Vulnerability in the Siebel CRM End User product of Oracle 
Siebel CRM  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83212 (Vulnerability in the Siebel Apps - Self Service product of 
Oracle Sieb ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83211 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83210 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83209 (Vulnerability in the Siebel CRM Development product of Oracle 
Siebel C ...)
        TODO: check
 CVE-2026-83208 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83207 (Vulnerability in the Siebel CRM Development product of Oracle 
Siebel C ...)
        TODO: check
 CVE-2026-83206 (Vulnerability in the Oracle Banking Corporate Lending Process 
Manageme ...)
        TODO: check
 CVE-2026-83205 (Vulnerability in the Oracle Applications Framework product of 
Oracle E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83204 (Vulnerability in the Oracle Sourcing product of Oracle 
E-Business Suit ...)
        TODO: check
 CVE-2026-83203 (Vulnerability in the Siebel CRM End User product of Oracle 
Siebel CRM  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83202 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83201 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83200 (Vulnerability in the Oracle Process Manufacturing Intelligence 
product ...)
        TODO: check
 CVE-2026-83199 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83198 (Vulnerability in the Oracle Field Service product of Oracle 
E-Business ...)
        TODO: check
 CVE-2026-83197 (Vulnerability in the Siebel Apps - Financial Services product 
of Oracl ...)
        TODO: check
 CVE-2026-83196 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83195 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83194 (Vulnerability in the Oracle Depot Repair product of Oracle 
E-Business  ...)
        TODO: check
 CVE-2026-83193 (Vulnerability in the Siebel Apps - Life Sciences product of 
Oracle Sie ...)
        TODO: check
 CVE-2026-83192 (Vulnerability in the Siebel CRM End User product of Oracle 
Siebel CRM  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83191 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83190 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83189 (Vulnerability in the Oracle User Management product of Oracle 
E-Busine ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83188 (Vulnerability in the Oracle Depot Repair product of Oracle 
E-Business  ...)
        TODO: check
 CVE-2026-83187 (Vulnerability in the Oracle Common Applications Calendar 
product of Or ...)
@@ -1231,29 +1231,29 @@ CVE-2026-83187 (Vulnerability in the Oracle Common 
Applications Calendar product
 CVE-2026-83186 (Vulnerability in the Oracle Common Applications Calendar 
product of Or ...)
        TODO: check
 CVE-2026-83185 (Vulnerability in the Oracle Common Applications product of 
Oracle E-Bu ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83184 (Vulnerability in the Oracle Application Object Library product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83183 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83182 (Vulnerability in the Siebel CRM Development product of Oracle 
Siebel C ...)
        TODO: check
 CVE-2026-83181 (Vulnerability in the Siebel CRM Development product of Oracle 
Siebel C ...)
        TODO: check
 CVE-2026-83180 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83179 (Vulnerability in the Oracle Common Applications Calendar 
product of Or ...)
        TODO: check
 CVE-2026-83178 (Vulnerability in the Oracle Application Object Library product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83177 (Vulnerability in the Oracle One-to-One Fulfillment product of 
Oracle E ...)
        TODO: check
 CVE-2026-83176 (Vulnerability in the Oracle Common Applications product of 
Oracle E-Bu ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83175 (Vulnerability in the Oracle Application Object Library product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83174 (Vulnerability in the Oracle CRM Technical Foundation product 
of Oracle ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83173 (Vulnerability in the Oracle One-to-One Fulfillment product of 
Oracle E ...)
        TODO: check
 CVE-2026-83172 (Vulnerability in the Oracle Sales Online product of Oracle 
E-Business  ...)
@@ -1265,9 +1265,9 @@ CVE-2026-83170 (Vulnerability in the Oracle One-to-One 
Fulfillment product of Or
 CVE-2026-83169 (Vulnerability in the Oracle One-to-One Fulfillment product of 
Oracle E ...)
        TODO: check
 CVE-2026-83168 (Vulnerability in the Oracle Applications Manager product of 
Oracle E-B ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83167 (Vulnerability in the Oracle Application Object Library product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83166 (Vulnerability in the Oracle Customer Interaction History 
product of Or ...)
        TODO: check
 CVE-2026-83165 (Vulnerability in the Oracle Customer Interaction History 
product of Or ...)
@@ -1275,41 +1275,41 @@ CVE-2026-83165 (Vulnerability in the Oracle Customer 
Interaction History product
 CVE-2026-83164 (Vulnerability in the Oracle Customer Interaction History 
product of Or ...)
        TODO: check
 CVE-2026-83163 (Vulnerability in the Oracle Application Object Library product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83162 (Vulnerability in the Oracle Application Object Library product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83161 (Vulnerability in the Oracle Project Intelligence product of 
Oracle E-B ...)
        TODO: check
 CVE-2026-83160 (Vulnerability in the RDBMS component of Oracle Database 
Server.  Suppo ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83159 (Vulnerability in the Applications DBA product of Oracle 
E-Business Sui ...)
        TODO: check
 CVE-2026-83158 (Vulnerability in the Oracle Applications Manager product of 
Oracle E-B ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83157 (Vulnerability in the Oracle Applications Manager product of 
Oracle E-B ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83156 (Vulnerability in the Oracle XML Developers Kit component of 
Oracle Dat ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83155 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83154 (Vulnerability in the Siebel CRM End User product of Oracle 
Siebel CRM  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83153 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83152 (Vulnerability in the Oracle Project Intelligence product of 
Oracle E-B ...)
        TODO: check
 CVE-2026-83151 (Vulnerability in the Service Delivery Platform product of 
Oracle Fusio ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83150 (Vulnerability in Oracle Application Testing Suite.   The 
supported ver ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83149 (Vulnerability in Oracle Application Testing Suite.   The 
supported ver ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83148 (Vulnerability in Oracle Application Testing Suite.   The 
supported ver ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83147 (Vulnerability in the PeopleSoft Enterprise FIN Inventory 
Brazil produc ...)
        TODO: check
 CVE-2026-83146 (Vulnerability in the Siebel CRM End User product of Oracle 
Siebel CRM  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83145 (Vulnerability in the Siebel Apps - Customer Order Management 
product o ...)
        TODO: check
 CVE-2026-83144 (Vulnerability in the Siebel Apps - Customer Order Management 
product o ...)
@@ -1323,19 +1323,19 @@ CVE-2026-83141 (Vulnerability in the Oracle Field 
Service product of Oracle E-Bu
 CVE-2026-83140 (Vulnerability in the Oracle Field Service product of Oracle 
E-Business ...)
        TODO: check
 CVE-2026-83138 (Vulnerability in the Oracle Spares Management product of 
Oracle E-Busi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83137 (Vulnerability in the Oracle Spares Management product of 
Oracle E-Busi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83136 (Vulnerability in the Oracle Spares Management product of 
Oracle E-Busi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83135 (Vulnerability in the Oracle iStore product of Oracle 
E-Business Suite  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83134 (Vulnerability in the Oracle iStore product of Oracle 
E-Business Suite  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83133 (Vulnerability in the Oracle iStore product of Oracle 
E-Business Suite  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83132 (Vulnerability in the Oracle iStore product of Oracle 
E-Business Suite  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83131 (Vulnerability in the Oracle Web Applications Desktop 
Integrator produc ...)
        TODO: check
 CVE-2026-83130 (Vulnerability in the Oracle Site Hub product of Oracle 
E-Business Suit ...)
@@ -1357,29 +1357,29 @@ CVE-2026-83123 (Vulnerability in the Oracle Report 
Manager product of Oracle E-B
 CVE-2026-83122 (Vulnerability in the Oracle Report Manager product of Oracle 
E-Busines ...)
        TODO: check
 CVE-2026-83121 (Vulnerability in the Oracle Marketing product of Oracle 
E-Business Sui ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83120 (Vulnerability in the Oracle Alert product of Oracle E-Business 
Suite ( ...)
        TODO: check
 CVE-2026-83119 (Vulnerability in the Oracle User Management product of Oracle 
E-Busine ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83118 (Vulnerability in the Applications DBA product of Oracle 
E-Business Sui ...)
        TODO: check
 CVE-2026-83117 (Vulnerability in the Applications DBA product of Oracle 
E-Business Sui ...)
        TODO: check
 CVE-2026-83116 (Vulnerability in the Oracle Order Management product of Oracle 
E-Busin ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83115 (Vulnerability in the Oracle Applications Manager product of 
Oracle E-B ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83114 (Vulnerability in the Oracle Quality product of Oracle 
E-Business Suite ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83113 (Vulnerability in the Oracle Quality product of Oracle 
E-Business Suite ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83112 (Vulnerability in the Oracle Lease and Finance Management 
product of Or ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83111 (Vulnerability in the Oracle Partner Management product of 
Oracle E-Bus ...)
        TODO: check
 CVE-2026-83110 (Vulnerability in the Oracle Marketing product of Oracle 
E-Business Sui ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83109 (Vulnerability in the Oracle Forms product of Oracle Fusion 
Middleware  ...)
        TODO: check
 CVE-2026-83108 (Vulnerability in the Oracle Forms product of Oracle Fusion 
Middleware  ...)
@@ -1419,45 +1419,45 @@ CVE-2026-83092 (Vulnerability in the Oracle Field 
Service product of Oracle E-Bu
 CVE-2026-83091 (Vulnerability in the Oracle Field Service product of Oracle 
E-Business ...)
        TODO: check
 CVE-2026-83090 (Vulnerability in the Oracle Spares Management product of 
Oracle E-Busi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83089 (Vulnerability in the Oracle Alert product of Oracle E-Business 
Suite ( ...)
        TODO: check
 CVE-2026-83088 (Vulnerability in the RDBMS component of Oracle Database 
Server.  Suppo ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83087 (Vulnerability in the Siebel CRM Cloud Applications product of 
Oracle S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83086 (Vulnerability in the Siebel CRM Cloud Applications product of 
Oracle S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83085 (Vulnerability in the Siebel CRM Cloud Applications product of 
Oracle S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83084 (Vulnerability in the Oracle Marketing product of Oracle 
E-Business Sui ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83083 (Vulnerability in the Oracle Marketing product of Oracle 
E-Business Sui ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83082 (Vulnerability in the Oracle Marketing product of Oracle 
E-Business Sui ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83081 (Vulnerability in the Oracle Banking Corporate Lending product 
of Oracl ...)
        TODO: check
 CVE-2026-83080 (Vulnerability in the Oracle Banking Branch product of Oracle 
Financial ...)
        TODO: check
 CVE-2026-83079 (Vulnerability in the Siebel CRM Cloud Applications product of 
Oracle S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83078 (Vulnerability in the Siebel CRM Cloud Applications product of 
Oracle S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83077 (Vulnerability in the Siebel CRM Cloud Applications product of 
Oracle S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83076 (Vulnerability in the Oracle HR Intelligence product of Oracle 
E-Busine ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83075 (Vulnerability in the Siebel CRM Cloud Applications product of 
Oracle S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83074 (Vulnerability in the Siebel CRM Cloud Applications product of 
Oracle S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83073 (Vulnerability in the Siebel CRM Cloud Applications product of 
Oracle S ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83072 (Vulnerability in the Oracle Applications Framework product of 
Oracle E ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83071 (Vulnerability in the Oracle Business Intelligence Enterprise 
Edition p ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83070 (Vulnerability in the PeopleSoft Enterprise PRTL Interaction 
Hub produc ...)
        TODO: check
 CVE-2026-83069 (Vulnerability in the Oracle Fusion Middleware Control product 
of Oracl ...)
@@ -1469,9 +1469,9 @@ CVE-2026-83067 (Vulnerability in the Oracle JDeveloper 
product of Oracle Fusion
 CVE-2026-83066 (Vulnerability in the Oracle Internet Directory product of 
Oracle Fusio ...)
        TODO: check
 CVE-2026-83065 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83064 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83063 (Vulnerability in the Oracle Internet Directory product of 
Oracle Fusio ...)
        TODO: check
 CVE-2026-83062 (Vulnerability in the Oracle Internet Directory product of 
Oracle Fusio ...)
@@ -1493,119 +1493,119 @@ CVE-2026-83055 (Vulnerability in the Oracle Internet 
Directory product of Oracle
 CVE-2026-83054 (Vulnerability in the Oracle Internet Directory product of 
Oracle Fusio ...)
        TODO: check
 CVE-2026-83053 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83052 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83051 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83050 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83049 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83048 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83047 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83046 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83045 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83044 (Vulnerability in the Oracle XML Gateway product of Oracle 
E-Business S ...)
        TODO: check
 CVE-2026-83043 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83042 (Vulnerability in the Oracle Identity Manager product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83041 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83040 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83039 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83038 (Vulnerability in the Oracle WebLogic Server product of Oracle 
Fusion M ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83037 (Vulnerability in the Oracle WebCenter Sites product of Oracle 
Fusion M ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83036 (Vulnerability in the Oracle WebCenter Sites product of Oracle 
Fusion M ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83035 (Vulnerability in the Oracle WebCenter Sites product of Oracle 
Fusion M ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83034 (Vulnerability in the Oracle WebCenter Sites product of Oracle 
Fusion M ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83033 (Vulnerability in the Oracle WebCenter Sites product of Oracle 
Fusion M ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83032 (Vulnerability in the Oracle WebCenter Sites product of Oracle 
Fusion M ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83031 (Vulnerability in the Oracle WebCenter Sites product of Oracle 
Fusion M ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83030 (Vulnerability in the Oracle Managed File Transfer product of 
Oracle Fu ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83029 (Vulnerability in the Oracle Managed File Transfer product of 
Oracle Fu ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83028 (Vulnerability in the Oracle Identity Manager Connector product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83027 (Vulnerability in the Oracle Identity Manager Connector product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83026 (Vulnerability in the Oracle Identity Manager Connector product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83025 (Vulnerability in the Oracle Identity Manager Connector product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83024 (Vulnerability in the Oracle Identity Manager Connector product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83023 (Vulnerability in the Oracle Identity Manager Connector product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83022 (Vulnerability in the Oracle WebCenter Enterprise Capture 
product of Or ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83021 (Vulnerability in the Oracle WebLogic Server product of Oracle 
Fusion M ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83020 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
        TODO: check
 CVE-2026-83019 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83018 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83017 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83016 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83015 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83014 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83013 (Vulnerability in the Oracle WebCenter Enterprise Capture 
product of Or ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83012 (Vulnerability in the Oracle WebCenter Enterprise Capture 
product of Or ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83011 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
        TODO: check
 CVE-2026-83010 (Vulnerability in the Oracle WebCenter Enterprise Capture 
product of Or ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83009 (Vulnerability in the Oracle WebCenter Enterprise Capture 
product of Or ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83008 (Vulnerability in the Oracle WebCenter Enterprise Capture 
product of Or ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83007 (Vulnerability in the Oracle WebCenter Enterprise Capture 
product of Or ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83006 (Vulnerability in the Oracle WebCenter Enterprise Capture 
product of Or ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83005 (Vulnerability in the Oracle WebCenter Enterprise Capture 
product of Or ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83004 (Vulnerability in the Oracle WebCenter Enterprise Capture 
product of Or ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83003 (Vulnerability in the Oracle WebCenter Enterprise Capture 
product of Or ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83002 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83001 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-83000 (Vulnerability in the Service Delivery Platform product of 
Oracle Fusio ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-82999 (Vulnerability in the Service Delivery Platform product of 
Oracle Fusio ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-82998 (Vulnerability in the Service Delivery Platform product of 
Oracle Fusio ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-82997 (Vulnerability in the Service Delivery Platform product of 
Oracle Fusio ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-82996 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
        TODO: check
 CVE-2026-82995 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
@@ -1613,9 +1613,9 @@ CVE-2026-82995 (Vulnerability in the Oracle Platform 
Security for Java product o
 CVE-2026-82994 (Vulnerability in the Oracle Platform Security for Java product 
of Orac ...)
        TODO: check
 CVE-2026-82993 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-82992 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-82964 (Improper preservation of permissions in the Avast sandbox 
minifilter d ...)
        TODO: check
 CVE-2026-82567 (The myPRO Manager notification gateway exposes an 
unauthenticated HTTP ...)
@@ -1625,21 +1625,21 @@ CVE-2026-82410 (Pocketbase is an open source web 
backend written in go. Prior to
 CVE-2026-82399 (CoreDNS is a DNS server written in Go. Prior to 1.14.7, the 
DNS-over-H ...)
        TODO: check
 CVE-2026-82311 (Apache Airflow FAB provider: resetting a user's password does 
not dele ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82310 (Apache Airflow FAB provider: deactivating a user account does 
not stop ...)
-       TODO: check
+       NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82126 (The Schema & Structured Data for WP & AMP WordPress plugin 
before 1.66 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-82125 (The Schema & Structured Data for WP & AMP WordPress plugin 
before 1.66 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-82124 (The Schema & Structured Data for WP & AMP WordPress plugin 
before 1.66 ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-81927 (Concrete CMS before 9.5.3 contained a stored cross-site 
scripting vuln ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-81926 (Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page 
paths b ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-81925 (Concrete CMS before 9.5.3 improperly neutralized a 
user-supplied custo ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-81876 (HAPI FHIR is a complete implementation of the HL7 FHIR 
standard for he ...)
        TODO: check
 CVE-2026-81875 (HAPI FHIR is a complete implementation of the HL7 FHIR 
standard for he ...)
@@ -1651,29 +1651,29 @@ CVE-2026-81326 (QND uses a hard-coded cryptographic 
key, which may allow a local
 CVE-2026-81176 (Svelte devalue is a JavaScript library that serializes values 
into str ...)
        TODO: check
 CVE-2026-7514 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-79994 (The guest-to-host Unix-domain socket relay in Docker Sandboxes 
validat ...)
        TODO: check
 CVE-2026-79993 (The `deleteContainer` opcode (0x14/20) is processed without 
verifying  ...)
        TODO: check
 CVE-2026-79708 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-79651 (A flaw was found in the theme localization endpoints of the 
keycloak-s ...)
        TODO: check
 CVE-2026-79298 (An issue in Howyar Technologies Inc SysReturn Versions prior 
to 11.3.0 ...)
        TODO: check
 CVE-2026-78474 (The Ni WooCommerce Sales Report  WordPress plugin before 4.2.0 
does no ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-78472 (The Ni WooCommerce Sales Report  WordPress plugin before 4.2.0 
does no ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-78252 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-78225 (A hardcoded cryptographic server key vulnerability exists in 
the deplo ...)
        TODO: check
 CVE-2026-78088 (The Contest Gallery \u2013 Upload & Vote Photos, Media, Sell 
with PayP ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77702 (The Eventin  WordPress plugin before 4.1.24 does not prevent 
the token ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-77412 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 
1.13.0, readFi ...)
        TODO: check
 CVE-2026-77411 (RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 
1.13.0, readLo ...)
@@ -1699,7 +1699,7 @@ CVE-2026-77401 (Zope AccessControl provides a general 
security framework for use
 CVE-2026-77360 (oRPC is an tool that helps build APIs that are end-to-end 
type-safe an ...)
        TODO: check
 CVE-2026-77190 (On affected platforms running Arista EOS, an unauthenticated 
attacker  ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-76873 (Netcore NR255-V version 1.5.130703 contains a stored 
cross-site script ...)
        TODO: check
 CVE-2026-76872 (Netcore NR255-V version 1.5.130703 contains a stored 
cross-site script ...)
@@ -1753,99 +1753,99 @@ CVE-2026-76820 (OpenCTI is an open source platform for 
managing cyber threat int
 CVE-2026-76796 (The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO 
Connect De ...)
        TODO: check
 CVE-2026-76707 (A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways 
could al ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76706 (A vulnerability in the API endpoint of HPE Networking 
EdgeConnect SD-W ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76705 (A buffer overflow vulnerability exists in the API endpoint of 
HPE Netw ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76704 (A vulnerability in the web-based management interface of the 
EdgeConne ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76703 (A buffer overflow vulnerability exists in the web-based 
management int ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76702 (A vulnerability in the operating system of HPE Networking 
EdgeConnect  ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76701 (A vulnerability in the API endpoint of HPE Networking 
EdgeConnect SD-W ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76700 (Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways 
could al ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76699 (A buffer overflow vulnerability exists in a system service 
within the  ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76698 (A command injection vulnerability exists in the web-based 
management i ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76697 (A vulnerability in the web-based management interface of HPE 
Networkin ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76696 (A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways 
could al ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76695 (Buffer overflow vulnerabilities exist in the underlying 
operating syst ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76694 (A privilege escalation vulnerability exists in the command 
line interf ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76693 (A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways 
could al ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76692 (A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways 
could al ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76691 (Buffer overflow vulnerabilities exist in the API endpoint of 
HPE Netwo ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76690 (A vulnerability exists in a component of the HPE Networking 
EdgeConnec ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76689 (A vulnerability exists in the configuration processing logic 
of the af ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76688 (Vulnerabilities have been identified in the web-based 
management inter ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76687 (A vulnerability in the API endpoint of HPE Networking 
EdgeConnect SD-W ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76686 (A vulnerability exists in the underlying operating system of 
HPE Netwo ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76685 (A vulnerability exists in the proxy packet processing logic of 
the aff ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76684 (Vulnerabilities have been identified in the API of HPE 
Networking Edge ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76683 (Buffer overflow vulnerabilities exist in the API endpoint of 
HPE Netwo ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76682 (A vulnerability in the network security monitoring component 
of intrus ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76681 (A vulnerability in the API of EdgeConnect SD-WAN Orchestrator 
could al ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76680 (Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator 
could al ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76679 (Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways 
could al ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76678 (A vulnerability in the API endpoint of HPE Networking 
EdgeConnect SD-W ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76677 (A privilege escalation vulnerability exists in the API of 
EdgeConnect  ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76676 (Buffer overflow vulnerabilities exist in the underlying 
operating syst ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76675 (A command injection vulnerability exists in the command line 
interface ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76674 (Buffer overflow vulnerabilities exist in the underlying 
operating syst ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76673 (Vulnerabilities have been identified in the API of EdgeConnect 
SD-WAN  ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76672 (A vulnerability exists in the SD-WAN Orchestrator that may 
lead to the ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76670 (Privilege escalation vulnerabilities exist in the API of HPE 
Networkin ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76669 (Privilege escalation vulnerabilities exist in the API of HPE 
Networkin ...)
-       TODO: check
+       NOT-FOR-US: HPE
 CVE-2026-76559 (The WP Import Export Lite WordPress plugin before 3.9.33 does 
not prop ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76558 (The WP Import Export Lite WordPress plugin before 3.9.33 does 
not esca ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76557 (The WP Import Export Lite WordPress plugin before 3.9.33 does 
not prop ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76556 (The WP Import Export Lite WordPress plugin before 3.9.33 does 
not prop ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76555 (The WP Import Export Lite WordPress plugin before 3.9.33 does 
not vali ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76553 (The WP Import Export Lite WordPress plugin before 3.9.33 does 
not vali ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76552 (The WP Import Export Lite WordPress plugin before 3.9.33 does 
not vali ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76551 (The WP Import Export Lite WordPress plugin before 3.9.33 does 
not rest ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76550 (The WP Import Export Lite WordPress plugin before 3.9.34 does 
not vali ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-76420 (A vulnerability in the internal configuration of the Apache 
JServ Prot ...)
        TODO: check
 CVE-2026-76187 (Apache Airflow Keycloak provider: the unauthenticated token 
endpoint a ...)
@@ -1855,181 +1855,181 @@ CVE-2026-76186 (Apache Airflow Keycloak provider: 
from Airflow 3.3 the Keycloak
 CVE-2026-76151 (Out-of-bounds read (buffer over-read) in the HTTP 
Cache-Control respon ...)
        TODO: check
 CVE-2026-76104 (Dell ObjectScale, versions prior to 4.4.0.0, contains an 
Incorrect Per ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-75516 (The RabbitMQ Java client library allows Java and JVM-based 
application ...)
        TODO: check
 CVE-2026-75025 (Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue 
where Mat ...)
        TODO: check
 CVE-2026-74926 (The MultiVendorX  WordPress plugin before 5.0.16 does not 
verify that  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-74909 (Keycloak provides a policy enforcer to protect applications by 
matchin ...)
        TODO: check
 CVE-2026-73966 (Vulnerability in the Siebel Apps - Marketing product of Oracle 
Siebel  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73965 (Vulnerability in the Siebel CRM Deployment product of Oracle 
Siebel CR ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73963 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73962 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73961 (Vulnerability in the Oracle JDeveloper product of Oracle 
Fusion Middle ...)
        TODO: check
 CVE-2026-73960 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73959 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73958 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73957 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73956 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73955 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73954 (Vulnerability in the PeopleSoft Enterprise PeopleTools product 
of Orac ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73953 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73952 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73951 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73950 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73949 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73948 (Vulnerability in the Oracle WebCenter Portal product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73947 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73946 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73945 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73944 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73943 (Vulnerability in the Oracle Identity Manager product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73942 (Vulnerability in the Oracle Identity Manager product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73941 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73940 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73926 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-73807 (The mySCADA myPRO Manager command API does not properly 
enforce authen ...)
        TODO: check
 CVE-2026-73469 (When specific platforms are using Arista EOS with a loose 
Unicast Reve ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73468 (A specially crafted packet can cause the premature expiry of 
multicast ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73464 (On affected platforms running Arista EOS with gRPC Network 
Management  ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73463 (On affected platforms running Arista EOS, when multiple gRPC 
Network S ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73461 (On affected EOS platforms with AAA-based gRPC authorization 
enabled fo ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73460 (On affected platforms running Arista EOS with IS-IS graceful 
restart e ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73459 (On affected platforms running Arista EOS with IS-IS 
configured, an una ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73458 (On affected platforms running Arista EOS with authenticated 
Bidirectio ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73457 (Under certain circumstances on affected platforms running 
Arista EOS w ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73456 (Under certain circumstances on affected platforms running 
Arista EOS w ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73455 (On affected platforms running Arista EOS with Open Shortest 
Path First ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73454 (On affected platforms running Arista EOS with gRPC Network 
Security In ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73453 (An unauthenticated P4Runtime (Programming Protocol-Independent 
Packet  ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73450 (On affected platforms running Arista EOS with MLAG Dual 
Primary Detect ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73447 (A privileged attacker can exploit certain operation to execute 
arbitra ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73446 (On affected platforms running Arista EOS with IS-IS configured 
on a br ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73445 (On affected platforms running Arista EOS, an issue with the 
gRPC Netwo ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73444 (On affected platforms running Arista EOS with VRRPv2 IP 
Authentication ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73443 (On affected platforms running Arista EOS with VRRPv2 IP-AH 
authenticat ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73442 (On affected platforms running Arista EOS with VRRP enabled, 
the peer d ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73440 (On affected platforms running Arista EOS with Simple Network 
Managemen ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73439 (On affected platforms running Arista EOS, if OpenConfig is 
configured  ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73438 (On affected platforms running Arista EOS with Open Shortest 
Path First ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73437 (On affected platforms running Arista EOS with Dynamic Host 
Configurati ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73436 (On affected platforms running Arista EOS with OSPFv2 and 
OSPFv2 segmen ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73435 (On affected platforms running Arista EOS with Open Shortest 
Path First ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-73177 (Nozomi Networks Labs identified a CWE-345: Insufficient 
Verification o ...)
-       TODO: check
+       NOT-FOR-US: Advantech
 CVE-2026-73176 (Nozomi Networks Labs identified a CWE-78: Improper 
Neutralization of S ...)
-       TODO: check
+       NOT-FOR-US: Advantech
 CVE-2026-73175 (Nozomi Networks Labs identified a CWE-400: Uncontrolled 
Resource Consu ...)
-       TODO: check
+       NOT-FOR-US: Advantech
 CVE-2026-73174 (Nozomi Networks Labs identified a CWE-319: Cleartext 
Transmission of S ...)
-       TODO: check
+       NOT-FOR-US: Advantech
 CVE-2026-73173 (Nozomi Networks Labs identified a CWE-306: Missing 
Authentication for  ...)
-       TODO: check
+       NOT-FOR-US: Advantech
 CVE-2026-73172 (Nozomi Networks Labs identified a CWE-78: Improper 
Neutralization of S ...)
-       TODO: check
+       NOT-FOR-US: Advantech
 CVE-2026-73171 (Nozomi Networks Labs identified a CWE-73: External Control of 
File Nam ...)
-       TODO: check
+       NOT-FOR-US: Advantech
 CVE-2026-73170 (Nozomi Networks Labs identified a CWE-94: Improper Control of 
Generati ...)
-       TODO: check
+       NOT-FOR-US: Advantech
 CVE-2026-73169 (Nozomi Networks Labs identified a CWE-79: Improper 
Neutralization of I ...)
-       TODO: check
+       NOT-FOR-US: Advantech
 CVE-2026-73167 (Nozomi Networks Labs identified a CWE-78: Improper 
Neutralization of S ...)
-       TODO: check
+       NOT-FOR-US: Advantech
 CVE-2026-73166 (Nozomi Networks Labs identified a CWE-94: Improper Control of 
Generati ...)
-       TODO: check
+       NOT-FOR-US: Advantech
 CVE-2026-73165 (Nozomi Networks Labs identified a CWE-78: Improper 
Neutralization of S ...)
-       TODO: check
+       NOT-FOR-US: Advantech
 CVE-2026-73164 (Nozomi Networks Labs identified a CWE-78: Improper 
Neutralization of S ...)
-       TODO: check
+       NOT-FOR-US: Advantech
 CVE-2026-73163 (Nozomi Networks Labs identified a CWE-78: Improper 
Neutralization of S ...)
-       TODO: check
+       NOT-FOR-US: Advantech
 CVE-2026-71182 (Dell Update Package Framework, versions prior to 26.07.03, 
contains an ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-71181 (Dell Update Package Framework, versions prior to 26.07.03, 
contains an ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-71180 (Dell Update Package Framework, versions prior to 26.07.03, 
contains an ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-71179 (Dell Update Package Framework, versions prior to 26.07.03, 
contains an ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-71163 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-71133 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-71047 (Vulnerability in the Oracle Identity Manager product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-70915 (Vulnerability in the Oracle Identity Manager product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-70913 (Vulnerability in the Oracle Identity Manager product of Oracle 
Fusion  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-70757 (Vulnerability in the Oracle WebLogic Server product of Oracle 
Fusion M ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-70756 (Vulnerability in the Oracle WebLogic Server product of Oracle 
Fusion M ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-70755 (Vulnerability in the Oracle Web Applications Desktop 
Integrator produc ...)
        TODO: check
 CVE-2026-70748 (Vulnerability in the Oracle WebLogic Server product of Oracle 
Fusion M ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-70416 (Dell ObjectScale, versions prior to 4.4.0.0, contains a 
Deserializatio ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-69486 (Heap-based buffer overflow in Microsoft Edge (Chromium-based) 
allows a ...)
-       TODO: check
+       NOT-FOR-US: Microsoft
 CVE-2026-69218 (Http4s is a Scala interface for HTTP services. Prior to 
0.23.35 and 1. ...)
        TODO: check
 CVE-2026-69217 (Http4s is a Scala interface for HTTP services. Prior to 
0.23.35 and 1. ...)
@@ -2069,11 +2069,11 @@ CVE-2026-68904 (node-opcua is an OPC UA implementation 
for TypeScript and Node.j
 CVE-2026-68536 (Server-Side Request Forgery / Local File Inclusion in Apache 
MyFace Co ...)
        TODO: check
 CVE-2026-68531 (Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard 
character ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-68530 (Concrete CMS 9 through 9.5.2 did not perform an authorization 
check on ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-68529 (Concrete CMS 9.0.0 through 9.5.2 was missing an authorization 
check on ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-68491 (An insufficient check allowed for the overwrite of arbitrary 
files via ...)
        TODO: check
 CVE-2026-68070 (The affected products are missing authentication for a 
critical functi ...)
@@ -2097,7 +2097,7 @@ CVE-2026-63127 (RMCP is an official Rust SDK for the 
Model Context Protocol. Pri
 CVE-2026-63126 (Wire provides gRPC and protocol buffers for Android, Kotlin, 
Swift, an ...)
        TODO: check
 CVE-2026-62597 (Vulnerability in the Oracle Enterprise Manager Base Platform 
product o ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-61709 (OpenFGA is an authorization and permission engine built for 
developers ...)
        TODO: check
 CVE-2026-61598 (djust provides Phoenix LiveView-style reactive server-side 
rendering f ...)
@@ -2121,7 +2121,7 @@ CVE-2026-61544 (libp2p-rust is the official Rust language 
implementation of the
 CVE-2026-61396
        REJECTED
 CVE-2026-5920 (The Bold Page Builder plugin for WordPress is vulnerable to 
Stored Cro ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-59974 (Stanza is a Stanford NLP Python library for tokenization, 
sentence seg ...)
        TODO: check
 CVE-2026-59969 (Apache ZooKeeper quorum TLS fails to enforce peer hostname 
verificatio ...)
@@ -2137,7 +2137,7 @@ CVE-2026-58146 (WNC T-Mobile 5G Box IDU router is 
vulnerable to OS command injec
 CVE-2026-57173 (vLLM is an inference and serving engine for large language 
models. Pri ...)
        TODO: check
 CVE-2026-56719 (MikroTik RouterOS before 7.24 contains an out-of-bounds read 
vulnerabi ...)
-       TODO: check
+       NOT-FOR-US: MikroTik
 CVE-2026-54544 (Fireshare facilitates self-hosted media and link sharing. 
Prior to ver ...)
        TODO: check
 CVE-2026-54337 (Fireshare facilitates self-hosted media and link sharing. 
Prior to ver ...)
@@ -2159,13 +2159,13 @@ CVE-2026-40855 (WNC T-Mobile 5G Box IDU router is 
vulnerable to a command inject
 CVE-2026-40854 (WNC T-Mobile 5G Box IDU router contains an authentication 
bypass vulne ...)
        TODO: check
 CVE-2026-3855 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-38999 (A Null Pointer Dereference in the mk_sched_event_close 
function (mk_se ...)
        TODO: check
 CVE-2026-32599 (Netmaker makes networks with WireGuard. Prior to version 
1.5.0, the `s ...)
        TODO: check
 CVE-2026-2380 (On affected platforms running Arista EOS with 
OpenConfig-related servi ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-27565 (An unauthenticated remote attacker can upload a malicious IODD 
file th ...)
        TODO: check
 CVE-2026-27564 (A high-privileged remote attacker can exploit a command 
injection vuln ...)
@@ -2207,11 +2207,11 @@ CVE-2026-27547 (A low-privileged remote attacker can 
exploit a command injection
 CVE-2026-27546 (An unauthenticated remote attacker can exploit an 
authentication bypas ...)
        TODO: check
 CVE-2026-26947 (Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell 
ObjectScale versio ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2026-20331 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
        TODO: check
 CVE-2026-20307 (A vulnerability in the web-based management interface of Cisco 
ISE cou ...)
-       TODO: check
+       NOT-FOR-US: Cisco
 CVE-2026-20306 (A vulnerability in the REST API of Cisco ISE and ISE-PIC could 
allow a ...)
        TODO: check
 CVE-2026-20305 (A vulnerability in the diagnostic tools of Cisco ISE and 
ISE-PIC could ...)
@@ -2219,69 +2219,69 @@ CVE-2026-20305 (A vulnerability in the diagnostic tools 
of Cisco ISE and ISE-PIC
 CVE-2026-20234 (As part of Cisco's ongoing commitment to proactive security 
and produc ...)
        TODO: check
 CVE-2026-1168 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-19857 (The Formidable Forms WordPress plugin before 6.35 does not 
prevent a r ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-19655 (On affected platforms running Arista EOS with Dynamic Host 
Configurati ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-19640 (On affected platforms running Arista EOS, an authenticated 
user with a ...)
-       TODO: check
+       NOT-FOR-US: Arista Networks
 CVE-2026-19619 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-19607 (A flaw was found in the first-broker-login flow of the 
keycloak-servic ...)
        TODO: check
 CVE-2026-19535 (Nozomi Networks Labs identified a CWE-352: Cross-Site Request 
Forgery  ...)
-       TODO: check
+       NOT-FOR-US: Advantech
 CVE-2026-19248 (QDomDocument XML parsing is vulnerable to a 
remotely-triggerable denia ...)
        TODO: check
 CVE-2026-18595 (The WP-Lister Lite for eBay plugin for WordPress is vulnerable 
to Stor ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18555 (The Better Messages \u2013 Chat Rooms, Group Chat, Private 
Messages &  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-18426 (Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level 
edit-pe ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-18425 (Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap 
reorder a ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-18424 (Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side 
Request Forge ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-18423 (Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure 
direct obje ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-18422 (Concrete CMS before 9.5.3 did not enforce a destination-side 
authoriza ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-18421 (Concrete CMS 9 through 9.5.2 does not perform an authorization 
check i ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-18212 (A flaw was found in the SAML Redirect Binding implementation 
of Keyclo ...)
        TODO: check
 CVE-2026-18120 (Concrete CMS before 9.5.3 exposed a legacy Express entry 
search endpoi ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS
 CVE-2026-17526 (Keycloak is an open-source identity and access management 
solution. A  ...)
        TODO: check
 CVE-2026-16794 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-16588 (The WP Directory Kit plugin for WordPress is vulnerable to 
blind SQL I ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-15640 (Under certain conditions a valid SAML IdP response may be used 
to impe ...)
-       TODO: check
+       NOT-FOR-US: Delinea
 CVE-2026-15639 (An attacker can craft a malicious link that, if used by a 
legitimate u ...)
-       TODO: check
+       NOT-FOR-US: Delinea
 CVE-2026-15638 (An unauthenticated user with access to Secret Server could 
leverage a  ...)
-       TODO: check
+       NOT-FOR-US: Delinea
 CVE-2026-14917 (A SAML authentication bypass vulnerability affects the Kong 
SAML plugi ...)
        TODO: check
 CVE-2026-14916 (A JWT signature verification vulnerability affects Kong 
components tha ...)
        TODO: check
 CVE-2026-14349 (The TrueBooker \u2013 Appointment Booking and Scheduler System 
plugin  ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13407 (The Royal Elementor Addons WordPress plugin before 1.7.1067 
does not p ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-13327 (Improper certificate validation on LDAPS connections to Active 
Directo ...)
-       TODO: check
+       NOT-FOR-US: Devolutions
 CVE-2026-12793 (The JetFormBuilder \u2014 Dynamic Blocks Form Builder plugin 
for WordP ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11996 (The Advanced Popups plugin for WordPress is vulnerable to 
Stored Cross ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-11984 (The Ad Inserter \u2013 Ad Manager & AdSense Ads plugin for 
WordPress i ...)
-       TODO: check
+       NOT-FOR-US: WordPress plugin
 CVE-2026-10150
        REJECTED
 CVE-2026-10149
@@ -2293,15 +2293,15 @@ CVE-2026-10144 (Rsbuild before 2.0.9 contains a command 
injection vulnerability
 CVE-2025-59953 (LMDeploy is a toolkit for compressing, deploying, and serving 
large la ...)
        TODO: check
 CVE-2025-43936 (Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, 
contains an I ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2025-36591 (Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell 
ObjectScale versio ...)
-       TODO: check
+       NOT-FOR-US: Dell / EMC
 CVE-2025-14871 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2025-11395 (A flaw was found in Podman. If an attacker can pass a crafted 
tar arch ...)
        TODO: check
 CVE-2024-11222 (GitLab has remediated an issue in GitLab CE/EE affecting all 
versions  ...)
-       TODO: check
+       NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-92238 (A maliciously constructed mail header could lead to multiple 
fields be ...)
        - thunderbird <unfixed>
 CVE-2026-92239 (A maliciously constructed IMAP line could cause an 
out-of-bounds buffe ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a0b09dbad77648c9cdd8e288a60a94bf2d5bbcf1

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a0b09dbad77648c9cdd8e288a60a94bf2d5bbcf1
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to