What you need to know today.
CISA adds actively exploited JetBrains TeamCity RCE to KEV; Fortinet auth bypass and critical Adobe Campaign Classic flaws also highlighted.

JetBrains TeamCity is facing a critical unauthenticated remote code execution vulnerability, CVE-2026-63077, which has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. This flaw allows attackers to execute arbitrary operating system commands without needing to log in, posing a significant risk to organizations using the affected versions. The vulnerability has reportedly been seen in the wild, prompting urgent calls for patching. Users are advised to upgrade to TeamCity versions 2026.1.3 or 2025.11.7 to mitigate this threat. As reported by The Hacker News, the exploitability of this flaw underscores the importance of timely security updates for development platforms.
A critical authentication bypass vulnerability, CVE-2022-40684, affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager, has been identified and is being actively exploited. This flaw allows attackers to bypass authentication mechanisms, potentially leading to unauthorized access and further compromise of network devices. The vulnerability impacts specific versions of FortiOS (7.2.0-7.2.1 and 7.0.0-7.0.6), FortiProxy (7.2.0 and 7.0.0-7.0.6), and FortiSwitchManager (7.2.0). Organizations using these products should prioritize updating to patched versions to prevent exploitation. As detailed by Securelist, this vulnerability has been linked to campaigns delivering malware like Cobalt Strike.
Multiple critical vulnerabilities have been disclosed in Adobe Campaign Classic (ACC), including CVE-2026-48331 (Server-Side Request Forgery), CVE-2026-48330 (SQL Injection), and CVE-2026-48323 (Template Engine vulnerability). These flaws could allow attackers to achieve arbitrary code execution and privilege escalation, with exploitation not requiring user interaction. The scope of these vulnerabilities has been noted as changed, indicating a potentially broader impact. Organizations using Adobe Campaign Classic should consult Adobe's security advisories for specific version information and apply necessary patches. Cyber Security News highlighted these critical issues, emphasizing the risk of code execution.
Critical vulnerabilities have been found in Apache Traffic Server, with CVE-2026-33267 being a notable example of an Improper Input Validation flaw. This vulnerability affects specific versions of Apache Traffic Server, namely 9.2.0 through 9.2.14 and 10.1.0 through 10.1.3. Exploitation could lead to various security compromises depending on the nature of the input validation failure. Users are strongly recommended to upgrade to versions 9.2.15 or 10.1.4, which contain the fixes for these issues. Vypr Intelligence reported on a batch of vulnerabilities affecting this software, underscoring the need for vigilance.
Microsoft's Active Directory Domain Services is affected by two elevation of privilege vulnerabilities, CVE-2021-42287 and CVE-2021-42278. While these vulnerabilities have been known for some time, their continued presence in the KEV catalog highlights their persistent risk. Successful exploitation could allow attackers to gain higher privileges within a compromised Active Directory environment, potentially leading to domain-wide compromise. Organizations should ensure their Active Directory environments are up-to-date and have implemented appropriate security configurations to mitigate these risks.
A critical command injection vulnerability in Webmin, CVE-2019-15107, affecting versions up to 1.920, has been added to the KEV catalog. This flaw allows remote attackers to execute arbitrary commands on the server by exploiting a parameter in the password_change.cgi script. Given its inclusion in the KEV list and its potential for remote command execution, prompt patching or mitigation is crucial for any system running vulnerable versions of Webmin. SentinelOne Labs noted this vulnerability in the context of cloud security risks.