Database/Control plane, storage & DevOps
JetBrains TeamCity: Deserialization in the agent polling protocol
CVSS 9.8CVE-2026-63077Control plane, storage & DevOpsKnown exploitedcurated
Impact
Deserialization in the agent polling protocol -> unauthenticated remote code execution on the CI server
Who can reach it
Network (remote)
What to do
Control-plane: URGENT upgrade to 2026.1.3/2025.11.7; rotate all build secrets and signing keys
References
Related entries
- JetBrains TeamCity: Authentication bypass leading to remote code execution on TeamCity ServerCVE-2023-42793 · JetBrains TeamCityCritical
- JetBrains TeamCity: Alternative-path authentication bypassCVE-2024-27198 · JetBrains TeamCityCritical
- Windows iSCSI Target Service (Windows Server 2012 through Windows Server 2025 / Windows 10 1607+): Three heap-basedCVE-2026-65791 · Windows iSCSI Target Service (Windows Server 2012 through Windows Server 2025 / Windows 10 1607+)Critical
- Windows Services for NFS: use-after-free in the ONCRPC XDR driver allows unauthenticated remote code executionCVE-2026-69595 · Windows Services for NFS (ONCRPC XDR driver)Critical
- Linux SUNRPC (xdr_buf_to_bvec, nfsd write path): xdr_buf_to_bvec stores a bio_vec before checking the slot is in rangeCVE-2026-72217 · Linux SUNRPC (xdr_buf_to_bvec, nfsd write path)Critical
- Linux VXLAN driver (transmit-path header pulls): `vxlan_xmit()`, `arp_reduce()` and `vxlan_mdb_entry_skb_get()`CVE-2026-74474 · Linux VXLAN driver (transmit-path header pulls)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.