TeamCity RCE, Fortinet Auth Bypass Added to CISA KEV
CISA adds JetBrains TeamCity RCE and Fortinet auth bypass to KEV; critical Adobe Campaign Classic flaws disclosed.

JetBrains TeamCity is facing scrutiny with the addition of CVE-2026-63077 to the CISA Known Exploited Vulnerabilities (KEV) catalog. This critical vulnerability, rated with a CVSS score of 9.8, allows for unauthenticated remote code execution via the agent polling protocol. Exploitation in the wild has been confirmed, prompting urgent calls for patching. Affected versions include TeamCity before 2026.1.3 and 2025.11.7. This flaw poses a significant risk to organizations relying on TeamCity for CI/CD pipelines, potentially leading to complete system compromise. As reported by The Hacker News, CISA's inclusion signifies a high-priority threat demanding immediate attention.
A critical authentication bypass vulnerability in Fortinet FortiOS and FortiProxy, tracked as CVE-2022-40684, has been added to the CISA KEV catalog. This flaw, with a CVSS score of 9.8, allows attackers to bypass authentication by using an alternate path or channel. It affects FortiOS versions 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, as well as FortiProxy versions 7.2.0 and 7.0.0 through 7.0.6. The vulnerability has been observed in the wild, with threat actors potentially leveraging it for unauthorized access to sensitive network devices. As detailed by The Hacker News, this vulnerability has been linked to the deployment of Cobalt Strike.
Multiple critical vulnerabilities in Adobe Campaign Classic (ACC) are being highlighted, including CVE-2026-48331 (SSRF), CVE-2026-48330 (SQL Injection), and CVE-2026-48323 (Template Injection). These flaws, all with a CVSS score of 10.0, could lead to arbitrary code execution and privilege escalation. Exploitation does not require user interaction, making them particularly dangerous. The scope of these vulnerabilities has been expanded, increasing the potential impact on organizations using ACC. Cyber Security News reports that these vulnerabilities enable arbitrary code execution, underscoring the severity of the threat.
Several critical vulnerabilities have been disclosed in Apache Traffic Server, with CVE-2026-33267 being a notable example of improper input validation. This issue affects versions 9.2.0 through 9.2.14 and 10.1.0 through 10.1.3. While not yet on the KEV catalog, the sheer number of disclosed vulnerabilities (25 in total, as noted by Vypr Intelligence) warrants attention. Patches are available in versions 9.2.15 and 10.1.4, and users are strongly advised to upgrade to mitigate potential risks.
Critical vulnerabilities in Oracle's Java Runtime Environment (JRE) from years ago, specifically CVE-2012-4681 and CVE-2012-1723, remain relevant due to their presence on the CISA KEV catalog. CVE-2012-4681, with a CVSS score of 9.8, allows remote attackers to execute arbitrary code by bypassing SecurityManager restrictions. CVE-2012-1723, also with a CVSS score of 9.8, affects confidentiality, integrity, and availability. These vulnerabilities impact Oracle Java SE 7 Update 6 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier. Their continued presence on the KEV list indicates persistent exploitation risks for outdated Java deployments.
Two privilege escalation vulnerabilities in Microsoft Active Directory Domain Services, CVE-2021-42287 and CVE-2021-42278, are also on the CISA KEV list. Both have a CVSS score of 7.5 and allow for elevation of privilege within a domain. While not remote code execution, these flaws can be chained with other vulnerabilities to gain deeper control over a network. Their inclusion in the KEV catalog suggests active exploitation, making it crucial for organizations to patch their Active Directory environments promptly. Help Net Security mentioned related AD vulnerabilities, highlighting the ongoing focus on AD security.
The critical CVE-2022-30190 vulnerability in Microsoft Support Diagnostic Tool (MSDT) is also present on the CISA KEV catalog. This flaw allows for remote code execution when MSDT is called via the URL protocol from applications like Microsoft Word. Attackers can exploit this to run arbitrary code with the privileges of the calling application. With a CVSS score of 7.8, it represents a significant threat, especially given its inclusion in the KEV list. Cyber Security News has noted its use in attacks.
A critical command injection vulnerability in Webmin, CVE-2019-15107, is also on the CISA KEV list. Affecting Webmin versions up to 1.920, this flaw in the password_change.cgi script allows for command injection. With a CVSS score of 9.8, it poses a severe risk to systems running vulnerable Webmin instances, enabling attackers to execute arbitrary commands. SentinelOne Labs has referenced this vulnerability, indicating its continued relevance in threat actor toolkits.
CVE-2017-12615, a critical vulnerability in Apache Tomcat, is also on the CISA KEV list. When running on Windows with HTTP PUTs enabled, this flaw allows attackers to upload a JSP file via a specially crafted request, leading to remote code execution. The vulnerability affects Tomcat versions 7.0.0 to 7.0.79. Its presence on the KEV catalog underscores the persistent risk associated with unpatched Tomcat instances, particularly in Windows environments.
Fortra's GoAnywhere MFT is affected by CVE-2023-0669, a pre-authentication command injection vulnerability. This critical flaw, with a CVSS score of 7.2, arises from deserializing an attacker-controlled object in the License Response Servlet. While patched, its inclusion on the KEV list indicates active exploitation. This vulnerability allows for arbitrary code execution before authentication, making it a high-priority target for attackers seeking to compromise managed file transfer solutions.
CVE-2026-5430, a critical vulnerability in JWT authentication mechanisms, allows for the acceptance of tokens signed with algorithms other than those explicitly configured. This can lead to security bypasses and potential unauthorized access. While its CVSS score is 10.0, it is not yet on the KEV catalog, suggesting it may be a newer discovery or one with less observed exploitation in the wild compared to others.
The Custom Fields WordPress plugin is vulnerable to CVE-2026-16940, a critical flaw allowing unauthenticated users to delete arbitrary files, including wp-config.php. This can lead to a full site takeover. The vulnerability affects versions before 1.5.1. Its critical nature and potential for complete site compromise make it a significant risk for WordPress users.
Adobe Campaign Classic (ACC) is also affected by CVE-2026-48330 (SQL Injection) and CVE-2026-48323 (Template Engine vulnerability), both critical flaws with CVSS scores of 10.0. These vulnerabilities can lead to arbitrary code execution within the context of the current user, posing a severe threat to data integrity and system security.
CVE-2009-3960, an unspecified vulnerability in Adobe BlazeDS affecting multiple Adobe products including LiveCycle and ColdFusion, is on the CISA KEV list. This medium-severity vulnerability (CVSS 6.5) allows remote attackers to gain unspecified access. Its long history and continued presence on the KEV list highlight the enduring risk of exploiting legacy vulnerabilities in widely deployed Adobe software.