Cicd
CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity via the Agent Polling Protocol
A deserialization flaw in TeamCity's agent polling protocol lets anyone with network access to the server run arbitrary OS commands with no login required — a direct hit on the CI/CD pipeline and everything it builds.
GitLab RCE PoC: Any Project Pusher Can Run Commands as Git via Notebook Diff Rendering
Researchers at depthfirst published working exploit code for an unfiled GitLab RCE: a two-bug chain in the Oj JSON parser behind Jupyter notebook diff rendering lets any user who can push to a project run commands as git on unpatched self-managed instances.