This week’s CVE of the Week is CVE-2026-63077, an unauthenticated remote code execution vulnerability in JetBrains TeamCity.
It is a deserialization issue in the popular CI/CD service, which leads to executing system commands in the operating system with recently published publicly available proof-of-concept exploit.
TeamCity is a build management and continuous integration/continuous delivery (CI/CD) server created by JetBrains. A vulnerability was disclosed on 27th July by the creators, revealing information about the case, then a proof-of-concept (PoC) was published by Rapid7 at 7th August.
The vulnerability, with a CVSS-score 9.8, has been identified only in TeamCity On-Premises. If the exploitation was successful from the attacker, it may let them bypass authentication via HTTP(S) protocol and execute arbitrary system commands.
Authentication bypass is achieved by the agent polling protocol when a deserialization happens. The exploit works with an XStream gadget chain that writes to the disk a polyglot SQL/JSP file and remote code execution is achieved with a GET request over HTTP(S) sent to the file on the disk.
JetBrains published mitigations on 7th August. Mitigations were published in version: 2025.11.7 or 2026.1.3, every version before these are affected.
Organizations using the vulnerable versions should update to the new versions. If something hooks the updates, then there are plugins for the affected versions. The plugin automatically downloads for TeamCity 2024.03 and newer versions. For TeamCity 2017.1 to 2018.1 it’s a manual work with server restart. Starting from TeamCity 2018.2 you can enable the plugin without restarting the server.
Critical vulnerability has been found with the CVSS score of 8.2 in CVE-2026-18577. Our CVE of the Week is about N-able N-central which provides customizations, automation, and integration to help your IT departments manage and secure your business. It [...]
This CVE of the Week is ‘Metabase SQL Injection Vulnerability’ (CVE-2026-72898) with an impressive score of 10.0. The exploit utilizes one of the oldest tool in the hackers’ toolbox: #SQLi. In the popular Open-source Business Intelligence tool, Metabase. Metabase enables users to query databases, create visualizations and build dashboard without writing any SQL code with ...
This week’s CVE of the Week is CVE-2026-24301, also known as CoSnitch, an exfiltration method in Microsoft Copilot that could allow an unauthorized attacker to steal sensitive information and data. With a CVSS score of 8.8, deserves serious attention. It is a combination of three different vulnerabilities that could allow an attacker to pull data ...
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.