Critical TeamCity RCE Flaw CVE-2026-63077 Demands Immediate Patching. JetBrains patched a CVSS 9.8 authentication bypass in TeamCity On-Premises that allows unauthenticated attackers to execute arbitrary commands via the agent polling protocol, potentially compromising entire CI/CD pipelines and the credentials stored within them.
VMware Patches Three Critical Flaws Enabling Auth Bypass and VM Escapes. Broadcom released emergency fixes for five vulnerabilities across vCenter, ESXi, Workstation, and Fusion, including two CVSS 9.8 flaws (CVE-2026-59309, CVE-2026-59310) that allow unauthenticated code execution and VM-to-host escape. Patching requires temporary service interruptions but is designated as emergency priority.
Ruby on Rails Patches Critical RCE in Active Storage (CVE-2026-66066). An unauthenticated attacker can read arbitrary files and achieve remote code execution in applications using libvips for image processing with untrusted uploads, potentially exposing secret_key_base and enabling full application compromise. No exploitation in the wild has been reported, but all secrets on affected deployments should be treated as compromised.
Google AI Finds 13-Year-Old Chrome Sandbox Escape, Drives Record 1,442-Flaw Patch Wave. Three Chrome releases (149, 150, 151) patched more vulnerabilities than the previous 23 combined, including CVE-2026-3545, a sandbox escape that had existed for 13 years. Google is now pushing twice-weekly updates and exploring dynamic patching as AI-assisted fuzzing permanently accelerates discovery cadence. Learn more
Key Takeaway
Prioritize patching TeamCity On-Premises, VMware vCenter/ESXi, and Rails Active Storage this week; all three have unauthenticated RCE potential and are common enterprise targets.
