JetBrains TeamCity
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
- CVSS
- 9.8
- EPSS
- -
- Published
- 2026.07.28
Review CVE severity, exploitation probability, known exploitation, affected versions, and remediation evidence without losing the primary-source trail.
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
Confirm the product, installed version, deployment path, and exposure.
Use KEV, EPSS, CVSS, and asset criticality as separate decision signals.
Follow the vendor-supported update or mitigation path and preserve rollback options.
Recheck versions, service health, access paths, logs, and residual indicators.
SECUFOCUS NOW links risk signals and source evidence, but does not treat a score as proof of exposure. Verify the affected product, version, configuration, and vendor guidance in your own environment before applying a change.
Read our methodology →