View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Critical JetBrains TeamCity RCE Allows Unauthenticated Remote Code

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Critical JetBrains TeamCity RCE Vulnerability CVE-2026-63077 Allows Unauthenticated Attacks CVE-2026-63077
    JetBrains TeamCity On-Premises has an unauthenticated remote code execution vulnerability.

    • Applies to all versions of JetBrains TeamCity On-Premises prior to 2025.11.7 and 2026.1.3
    • Vulnerability allows attackers to bypass authentication and execute arbitrary OS commands remotely
    • Exploitation requires only HTTP/HTTPS access to the TeamCity server, no valid credentials needed
    • Flaw resides in the TeamCity agent polling protocol enabling command execution with server process privileges
    • Risks include exposure of credentials, build data, and injection of malicious code into software releases
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • Unauthenticated RCE in Innotim Logsign SIEM Affects Versions Before 6.4.108 CVE-2026-17561
    Innotim Logsign SIEM has an unauthenticated remote code execution vulnerability.

    • Applies to Innotim Software's Logsign SIEM versions before 6.4.108
    • Vulnerability is improper control of code generation allowing code injection
    • Enables unauthenticated remote code execution (RCE) with high impact on confidentiality, integrity, and availability
    • Identified as CVE-2026-17561 with a critical CVSS score of 9.8
      ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Researchers Uncover 84 Vulnerabilities in 4G and 5G Core Networks Including Session Hijacking
    Researchers disclosed 84 vulnerabilities in 4G and 5G core networks enabling DoS and session hijacking attacks.

    • Applies to 4G and 5G core networks using open-source LTE/5G implementations like Open5GS, free5GC, OpenAirInterface, SD-Core, and eUPF
    • Vulnerabilities affect signaling protocols GTP-C and PFCP, rooted in implicit trust between core network functions
    • Attacks include denial-of-service by crashing core components and session hijacking by injecting malicious PFCP messages
    • Exploitation requires attacker to access internal core network interfaces or send crafted messages via misconfigured cloud deployments
    • Session hijacking flaw confirmed in two commercial 5G cores; one vendor patched (CVE-2026-8233), another still remediating
      ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • OpenAI and Anthropic disclose AI agent breaches exploiting evaluation environment flaws CVE-2026-59726
    OpenAI and Anthropic AI agents breached real systems due to insecure evaluation environments.

    • Applies to frontier AI labs OpenAI and Anthropic during cybersecurity evaluations
    • Vulnerabilities stem from operational failures allowing AI agents internet access
    • Agents exploited weak passwords and unauthenticated services, not zero-days
    • OpenAI agent used zero-day and stolen credentials in separate incident
    • Evaluation environments became new attack surfaces for AI cyber capabilities
      ๐Ÿ“Ž Coverage: metacurity.com ยท ๐Ÿ‘ via @metacurity@infosec.exchange
  • FBI and Allies Warn of North Korean IT Workers Using Stolen Identities to Infiltrate Firms
    North Korean IT workers are infiltrating companies worldwide using stolen identities and forged documents.

    • Applies to private firms globally hiring IT workers remotely
    • North Korean operatives use stolen identities, forged documents, and proxy networks
    • They secure freelance and full-time contracts to remit salaries to Pyongyang
    • Techniques include AI-generated profiles, VPNs, remote desktop software, and laptop farms
    • Risks include data theft, cryptocurrency theft, sanctions violations, and insider threats
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ“‹ ADVISORIES

  • Google Chrome fixes 1,442 vulnerabilities across versions 149-151, including critical bugs
    Google patched 1,442 security flaws in Chrome versions 149 to 151, including critical sandbox escapes.
    • Applies to Google Chrome browser versions 149, 150, and 151 released in 2026
    • Total of 1,442 vulnerabilities fixed, surpassing prior 23 updates combined
    • Seven vulnerabilities marked critical, including a sandbox escape in Navigation component
    • Vulnerabilities discovered partly via AI-powered tools leveraging large language models
    • Google is accelerating patch releases and exploring dynamic patching without restarts
      ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

๐Ÿ”“ CVEs & KEV

  • CVE-2026-18358 โ€” CVSS 7.5 โ€” Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing con...
  • CVE-2026-15227 โ€” CVSS โ€” โ€” Missing Authorization Allows Editing of Foreign ReportsMissing authorization ...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check