CVE-2026-63077
An unauthenticated remote code execution vulnerability exists in the JetBrains TeamCity agent polling protocol.
Critical vulnerabilities, curated daily for security professionals
The vulnerability landscape for Tuesday, August 11, 2026, was dominated by critical security flaws affecting e-commerce platforms, development tools, and travel management systems. Critical CVE counts increased by 2500 percent to 52, while high-priority vulnerabilities rose by 163 percent to 100 compared to the prior day. Notable disclosures include CVE-2026-63106 in Razinsoft Ready eCommerce, CVE-2026-72862 in Dokploy, and CVE-2026-12872 in the Webinfos WordPress plugin. Attack patterns reflect broad exposure across diverse software ecosystems, including two active exploits involving JetBrains TeamCity and Progress LoadMaster. Given the current 0 percent patch availability status across these new disclosures, organizations should prioritize monitoring vendor security portals for updates.
Immediate action: Security teams should immediately audit environments for Razinsoft, Dokploy, and TeamCity deployments to mitigate potential exposure. As patch availability remains at 0 percent, implement compensating controls such as network segmentation or web application firewall rules to restrict access to these services.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An unauthenticated remote code execution vulnerability exists in the JetBrains TeamCity agent polling protocol.
Progress LoadMaster and associated products are vulnerable to command injection, which allows unauthenticated attackers to execute arbitrary commands on the underlying system.
Ready eCommerce contains an unauthenticated SQL injection vulnerability in the product listing API, allowing attackers to extract database contents and potentially gain unauthorized system access.
Dokploy contains an OS command injection vulnerability in its database service deployment functions, allowing authenticated users to execute arbitrary commands on the remote server.
The react18-use library contained malicious code in a specific commit that executes remote attacker-controlled payloads on developer machines during the npm install process.
The react-tracked repository contained malicious commits that executed remote code on developer machines during npm install.
The use-reducer-async repository contained malicious commits that executed remote code on developer machines during npm install.
The Webinfos WordPress plugin fails to validate uploaded files or restrict access, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution.
The Win Men Intermational Travel Agency Management System is vulnerable to SQL injection, allowing unauthenticated remote attackers to manipulate database contents.
A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass access controls and read database contents via the Map-form @having operator.
An unauthenticated SQL injection vulnerability in TBEA TLogger V2.1.0.0B0.0.0.0 allows remote attackers to read, modify, or delete data in the device database via unsanitized HTTP parameters.
An OS command injection vulnerability in Dokploy prior to 0.29.13 allows authenticated users with backup permissions to execute arbitrary commands in the host context via crafted database names.
Metabase contains a critical SQL injection vulnerability in the password reset endpoint that allows unauthenticated remote attackers to gain full administrative control over the instance.
Dokploy contains a command injection vulnerability in its registry credential and Docker Swarm management endpoints, allowing authenticated users to execute arbitrary commands on the host.
A critical OS command injection vulnerability in crontab-ui allows unauthenticated remote attackers to execute arbitrary system commands by importing a malicious crontab database file.
An unrestricted file upload vulnerability in dulldusk phpfm through 1.8.0 allows unauthenticated attackers to execute arbitrary PHP code via the file manager.
A missing authentication flaw in dulldusk phpfm through 1.8.0 allows unauthenticated remote attackers to gain full administrative access to the filesystem.
Dokploy prior to 0.29.13 is vulnerable to OS command injection via the backup and restore pipeline, allowing authenticated admins to execute arbitrary commands on the host machine.
Dokploy versions before 0.29.13 are vulnerable to OS command injection via the registry testing functions, allowing authenticated users to execute arbitrary commands on the host or remote server.
Dokploy versions before 0.29.13 contain an authorization bypass and OS command injection flaw, allowing authenticated users to manipulate server IDs and execute commands on other tenants' servers.
Dokploy versions before 0.29.13 are vulnerable to OS command injection in the backup restore functionality, allowing authenticated users to execute arbitrary commands within the host context.
Dokploy versions before 0.29.13 are vulnerable to OS command injection via the dockerImage field, allowing authenticated users to execute arbitrary commands on build hosts.
The Insert or Embed Articulate Content into WordPress plugin fails to properly validate uploaded archives, allowing malicious file uploads and potential remote code execution.
Dokploy versions prior to 0.29.13 fail to enforce authorization checks on WebSocket handlers, allowing authenticated users to access interactive shells and escalate privileges to root.
Dokploy versions 0.28.8 and earlier are vulnerable to OS command injection via the filePath parameter, allowing authenticated users to execute arbitrary commands on remote servers.
TBEA TLogger contains a hard-coded root credential, allowing an unauthenticated remote attacker to gain administrative access via SSH.
The Super Store Finder WordPress plugin contains a SQL injection vulnerability in an unauthenticated AJAX action, allowing remote attackers to extract sensitive data from the database.
Dokploy allows a low-privileged member to execute arbitrary OS commands as root by injecting malicious input into the rclone configuration fields during test connection operations.
Dokploy improperly validates Bitbucket repository fields, allowing authenticated users to inject arbitrary OS commands into git clone operations.
Dokploy versions prior to 0.29.8 are vulnerable to OS command injection via the getRegistryCommands function, allowing authenticated users to execute arbitrary commands on the host server.
The SoftMarket Digital Marketplace WordPress plugin contains an authentication bypass flaw in its email-verification flow, allowing unauthenticated users to impersonate any verified account.
The Fabrik extension for Joomla is vulnerable to unauthenticated remote code execution via the ajax_calc feature of the calc plugin.
A deserialization flaw in the Feast component of Red Hat OpenShift AI allows remote attackers to execute arbitrary code via malicious user-defined functions.
An incomplete fix for a previous vulnerability allows authenticated users to perform OS command injection on remote servers managed by Dokploy through manipulated Traefik configuration settings.
Dokploy versions prior to 0.29.13 are susceptible to OS command injection via the volume backup functionality, allowing authenticated low-privilege users to execute commands with root-level impact.
Dokploy versions before 0.29.13 are vulnerable to a missing authorization flaw in the docker-container-terminal component, allowing authenticated users to gain a root shell in arbitrary containers.
Dokploy versions prior to 0.29.13 contain an OS command injection vulnerability in the compose update process, allowing authenticated users to execute arbitrary commands on the host system.
Dokploy versions 0.29.3 through 0.29.12 are susceptible to OS command injection due to insufficient server-side validation of git branch fields during deployment operations.
Dokploy versions before 0.29.13 contain an arbitrary file write and deletion vulnerability due to improper input validation in the certificate management service.
The AsyncFuncAI deepwiki-open application is vulnerable to path traversal, allowing unauthenticated remote attackers to read, write, or delete arbitrary files with root privileges.
The NASA fprime-gds application fails to implement authentication on its Flask-based endpoints, allowing unauthenticated remote attackers to execute arbitrary code and issue commands to spacecraft.
An OS command injection vulnerability in duhow/xiaoai-patch allows remote, unauthenticated attackers to execute arbitrary system commands via the silent query parameter in the /mute and /unmute endpoints.
An OS command injection vulnerability in alseambusher/crontab-ui allows unauthenticated remote attackers to inject arbitrary cron jobs by sending a crafted GET request with CRLF sequences.
A cross-tenant authorization bypass in Dokploy versions 0.29.8 and earlier allows authenticated users with backup permissions to access or poison backup data belonging to other organizations.
An improper authorization vulnerability in fosrl Pangolin through v1.20.0 allows an authenticated remote attacker to access resources across organizations by reusing valid access tokens.
An arbitrary file read and SSRF vulnerability in Firecrawl prior to 2.11.32 allows unauthenticated attackers to read local files via malicious JSON schemas during extraction.
An OS command injection vulnerability in Dokploy prior to 0.29.13 allows authenticated users with deployment permissions to execute arbitrary commands on the host by manipulating SSH host settings.
Metabase contains an SQL injection vulnerability allowing unauthenticated attackers to execute arbitrary SQL commands via manipulated field-filter parameters in shared dashboards.
ERPNext contains a template injection vulnerability that allows authenticated users to execute arbitrary server-side code by manipulating template parameters in processing functions.
SAP NetWeaver and ABAP Platform contain an out-of-bounds write vulnerability in the DIAG protocol parsing logic, enabling unauthenticated remote attackers to trigger memory corruption.
An OS command injection vulnerability in Zyxel WAH7601 allows unauthenticated remote attackers to execute arbitrary commands on the affected device.
An improper privilege management vulnerability in Dokploy allows authenticated users to escalate privileges and execute arbitrary scripts as root on the host machine.
An OS command injection vulnerability in the Dokploy backup endpoint allows authenticated users to execute arbitrary commands on the host server.
An unauthenticated XML external entity (XXE) vulnerability in Jaspersoft JasperReports Server allows remote attackers to read sensitive files or potentially cause a denial of service.
The ChamaWP WordPress plugin fails to validate input before deserialization, allowing unauthenticated attackers to potentially achieve remote code execution.
A vulnerability in the tapestry-core component of Apache Tapestry 5 allows for the unauthorized exposure of sensitive information to unauthenticated actors.
The xmysql application is vulnerable to path traversal, allowing unauthenticated remote attackers to read and download arbitrary files from the server.
SAP ABAP Developer Tools lacks authorization checks, allowing authenticated users with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP.
ManageEngine M365 Manager Plus and Security Plus are affected by an authenticated path traversal vulnerability in the Exchange Online backup module.
Apache Ranger client code is vulnerable to an improper TLS hostname verification issue, which could allow an attacker to perform man-in-the-middle attacks.
TYPO3 CMS v13 and v14 contain a flaw where referrer enforcement is ineffective, enabling potential Cross-Site Request Forgery (CSRF) attacks against authenticated users.
The Contact Form to Any API plugin for WordPress is vulnerable to information exposure, potentially allowing unauthenticated attackers to access sensitive data.
Apache Ranger contains a missing authentication vulnerability in its Download APIs, allowing unauthenticated attackers to potentially access sensitive information.
In the Linux kernel, the following vulnerability has been resolved: ALSA: compress: Fix task creation error unwind snd_compr_task_new() allocates the driver task before validating the returned DMA buffers and reserving file descriptors.
Jenkins contains an improper link resolution vulnerability that allows authenticated users to manipulate file paths during access operations.
The HT Contact Form WordPress plugin contains an information exposure vulnerability that may allow unauthenticated attackers to view sensitive data.
The Salon Booking System WordPress plugin is vulnerable to information exposure, allowing unauthenticated attackers to access sensitive data.
The File Manager WordPress plugin is susceptible to an information exposure vulnerability that permits unauthenticated access to sensitive files.
The File Manager WordPress plugin contains an information exposure vulnerability allowing unauthenticated attackers to access sensitive system resources.
The Login & Register Forms WordPress plugin contains an information exposure vulnerability that allows unauthenticated access to sensitive data.
Apache Ranger lacks adequate brute-force protection in its UnixAuth mechanism, allowing attackers to perform automated authentication attempts.
A bounds checking error in the Zephyr RTOS TLS subsystem allows local authenticated attackers to cause potential memory corruption or system instability.
A flaw in the Red Hat OpenShift AI MaaS Gateway involves improper access control, which could allow an authenticated user to perform unauthorized actions.
An OS command injection vulnerability in 4xmen/pm2panel allows an authenticated remote attacker to execute arbitrary system commands on the host by manipulating the id parameter.
A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch allows a remote attacker to force the Xiaomi smart speaker to make unauthorized requests to internal or external URLs.
A path traversal vulnerability in the mustafaakin cast-localvideo application allows unauthenticated remote attackers to read arbitrary files from the host server.
An untrusted pointer dereference vulnerability in various ASUS software components allows a local attacker to perform arbitrary memory writes, potentially leading to privilege escalation.
A missing authorization check in SAP Manufacturing Integration and Intelligence allows unauthenticated remote attackers to access sensitive scheduling-related functions.
In the Linux kernel, the following vulnerability has been resolved: binder: fix UAF in binder_free_transaction() In binder_free_transaction(), the t->to_proc is read under the t->lock.
An authentication bypass vulnerability in OpenSignLabs opensignserver allows remote attackers to circumvent security controls.
A security flaw in the Data Science Pipelines Operator for Red Hat OpenShift AI 3.3 allows for improper control of object attributes.
A vulnerability in the odh-dashboard component of Red Hat OpenShift AI allows authenticated attackers to perform operations with excessive privileges.
A security flaw exists in the odh-dashboard component of Red Hat OpenShift AI that may allow authenticated users to perform unauthorized operations.
A flaw in the Red Hat OpenShift AI overlay for the training operator allows authenticated attackers to perform unauthorized actions.
A vulnerability in the Red Hat OpenShift AI training-operator allows for execution with unnecessary privileges.
Cachet is susceptible to Server-Side Template Injection and authorization bypass vulnerabilities, allowing authenticated attackers to execute arbitrary code.
The TBEA TLogger communication box contains critical vulnerabilities including missing authentication and stack-based buffer overflows, which may lead to remote code execution or system denial of service.
Dokploy is affected by a missing authorization vulnerability, which allows authenticated users to perform unauthorized actions within the platform.
CyberPanel versions 2.4.3 and earlier are susceptible to a vulnerability involving insufficient verification of data authenticity, potentially leading to remote code execution.
CyberPanel versions 2.4.3 and earlier contain an OS command injection vulnerability in the StarRemoteTransfer functionality, which can be exploited by authenticated users.
Dokploy versions prior to 0.29.13 are vulnerable to OS command injection, which can be exploited by an authenticated user to achieve arbitrary command execution.
A missing authorization vulnerability in Dokploy allows authenticated users to perform unauthorized actions due to improper capability checks.
SPIP is vulnerable to code injection via the navigation endpoint on SQLite, allowing authenticated users to execute arbitrary code.
A cross-site request forgery vulnerability in FreePBX Framework 17 allows unauthenticated attackers to perform unauthorized actions by tricking a logged-in administrator.
TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced, allowing unauthenticated access.
A vulnerability in the Data Science Pipelines Operator for Red Hat OpenShift AI allows for execution with unnecessary privileges.
TBEA TLogger is susceptible to resource exhaustion due to improper allocation limits, allowing unauthenticated attackers to cause a denial of service.
Dokploy contains an OS command injection vulnerability, allowing authenticated users with low privileges to execute arbitrary commands on the underlying host.
Dokploy is affected by an OS command injection vulnerability, enabling authenticated users to execute arbitrary commands via improper input neutralization.
Dokploy is susceptible to OS command injection, allowing an authenticated attacker to execute arbitrary system commands on the host.
The Discourse discussion platform contains a cross-site scripting (XSS) vulnerability that allows authenticated users to execute malicious scripts in the context of other users.
Roskus Prospero Flow CRM contains an authorization bypass vulnerability in its permission management component, allowing authenticated users to perform unauthorized actions.
TP-Link Aginet devices contain an authorization bypass vulnerability allowing authenticated low-privileged users to perform unauthorized administrative actions.
TP-Link Aginet devices are susceptible to OS command injection due to improper input validation in web interface components.
Pega Infinity is affected by an improper verification of cryptographic signatures vulnerability, which allows authenticated attackers to potentially compromise data integrity and confidentiality.
Roskus Prospero Flow CRM contains an authorization bypass vulnerability in its contact management component, allowing authenticated users to access or modify data via user-controlled keys.
TP-Link Aginet devices use hardcoded cryptographic keys in their firmware, potentially allowing unauthorized decryption of sensitive configuration data.
A vulnerability in the Feast component within Red Hat OpenShift AI allows for execution with unnecessary privileges.
Dokploy contains an authorization bypass vulnerability allowing authenticated users to access resources via user-controlled keys.
An integer underflow vulnerability exists in the GIMP PSD file format plugin within Red Hat Enterprise Linux, potentially allowing for arbitrary code execution or system crashes.
HashiCorp Vault Enterprise is vulnerable to a cross-namespace authorization bypass that allows authenticated users to delete entity storage backing in unauthorized namespaces.
The Zyxel WAH7601 router contains an insufficiently protected credentials vulnerability that allows unauthenticated attackers to retrieve sensitive data.
A vulnerability exists in the trustyai-service-operator LMEvalJob controller of Red Hat OpenShift AI 3.3, allowing for incorrect privilege assignment.
Tabby terminal emulator is vulnerable to a path traversal flaw, allowing an attacker to potentially access or manipulate unauthorized files.
The unearth library is susceptible to a path traversal vulnerability via unnormalized paths and symlink escapes.
A flaw in the TrustyAI Service (TAS) deployment of Red Hat OpenShift AI 3.3 results in missing authentication for critical functions.
SAP BusinessObjects Business Intelligence Platform uses a hard-coded cryptographic key to store sensitive user credentials, risking unauthorized exposure.
The openvt utility in Red Hat Enterprise Linux contains an improper access control vulnerability when using the -u flag, potentially allowing unauthorized privilege escalation.
A flaw in libvirt involving improper link resolution during file access could allow a local attacker to manipulate file operations and potentially escalate privileges.
An out-of-bounds write vulnerability in the GIMP image manipulation program, specifically within the Seattle Filmworks file loader, may allow arbitrary code execution.
A vulnerability in the Feast and feast-operator components of Red Hat OpenShift AI 3.3 allows for unauthorized access due to missing authentication.
A server-side request forgery (SSRF) vulnerability in Automatisch allows authenticated users to make the server fetch arbitrary URLs and retrieve the response body.
A server-side request forgery (SSRF) vulnerability exists in the gabehf Koito library, potentially allowing unauthorized network requests.
SAP Manufacturing Integration and Intelligence contains an improper path validation vulnerability allowing privileged attackers to manipulate file operations.
A flaw in Red Hat OpenShift AI Data Science Pipelines (DSP) allows authenticated users to gain elevated privileges due to incorrect privilege assignment.
A stored cross-site scripting (XSS) vulnerability exists in Lobe-Chat versions through 2.2.13, allowing attackers to inject malicious scripts.
Chiline Cloud by Inventec Appliances contains an Insecure Direct Object Reference (IDOR) vulnerability that permits unauthorized access to data.
Mastodon is susceptible to an asymmetric resource consumption vulnerability due to the lack of proper limits or throttling on incoming requests.
Mastodon is vulnerable to an information exposure issue allowing unauthorized actors to access sensitive data due to a flaw in the application architecture.
The Data Science Pipelines Operator in Red Hat OpenShift AI 3.3 contains a flaw where a cryptographically weak pseudo-random number generator is utilized.
A resource allocation flaw in the ml-metadata component of Red Hat OpenShift AI 3.3 may allow an unauthenticated attacker to cause a denial-of-service condition.
A memory safety vulnerability in the UpdateHub firmware-update agent within the Zephyr RTOS allows an attacker to cause a denial of service via the probe handler.
Dokploy contains a critical missing authentication vulnerability in its platform management functions, allowing unauthorized actors to perform administrative actions.
Flowise is susceptible to a missing authorization vulnerability that allows unauthenticated attackers to perform unauthorized file downloads via the OpenAI Assistants integration.
The XWiki Platform contains a vulnerability leading to the exposure of private personal information to unauthorized actors through the livetable UI.
OpenSignLabs opensignserver contains a missing authentication vulnerability in critical functions, allowing unauthenticated remote access.
A broken object-level authorization vulnerability exists in OpenSignLabs opensignserver, allowing unauthorized access to restricted resources.
A missing authorization vulnerability in OpenSignLabs opensignserver allows unauthenticated attackers to perform unauthorized actions.
NASA HyperCP is vulnerable to OS command injection, which can be triggered by a network-adjacent attacker who manipulates responses from the oceandata service.
A NULL pointer dereference vulnerability exists in the Fastschema application, which may allow an unauthenticated attacker to cause a denial of service.
A missing authentication vulnerability in the Frangoteam FUXA platform allows unauthenticated remote attackers to access restricted functions.
A time-of-check/time-of-use (TOCTOU) race condition exists in Fastschema, which could potentially allow an unauthenticated attacker to manipulate system states.
A missing authorization check in SAP Manufacturing Integration and Intelligence allows unauthenticated attackers to send crafted requests to the Cost Servlet.
The kitty terminal emulator is susceptible to command injection, CRLF injection, and improper neutralization of escape sequences, which may lead to unauthorized code execution.
A flaw in GIMP file format plugins, specifically for PSD and PAA files, allows for out-of-bounds writes that can be triggered by processing malicious files.
Zyxel Networks WAH7601 contains a hard-coded credentials vulnerability that allows an attacker to read sensitive constants within the device executable.
In the Linux kernel, the following vulnerability has been resolved: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() When a container exits, the following BUG_ON() is occasionally triggered: ================================================================== VFS: Busy.
In the Linux kernel, the following vulnerability has been resolved: smb/client: fix chown/chgrp with SMB3 POSIX Extensions Ownership (chown) and group (chgrp) modifications were being ignored when mounting with SMB3 POSIX Extensions unless CIFS_MOUNT_CIFS_ACL or CIFS_MOUNT_MODE_FROM_SID were also.
In the Linux kernel, the following vulnerability has been resolved: smb: client: resolve SWN tcon from live registrations cifs_swn_notify() looks up a witness registration by id under cifs_swnreg_idr_mutex, drops the mutex, and then uses the registration's cached tcon pointer.
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns In the analysis pass of $LogFile journal replay, log_replay() copies LCNs from each action log record into an existing Dirty Page Table (DPT) entry without bound.
In the Linux kernel, the following vulnerability has been resolved: staging: media: ipu7: fix double-free and use-after-free in error paths In both ipu7_isys_init() and ipu7_psys_init(), pdata is allocated and then passed to ipu7_bus_initialize_device(), which stores it in adev->pdata.
In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: bound slave read/write to the kern_buf size The SLAVE-path helpers buffer_to_user() and buffer_from_user() copy 'count' bytes into/out of the fixed-size kern_buf (size_buf == PCI_BUF_SIZE == 0x20000, 128 KiB) us.
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/cs35l41: Fix firmware load work teardown cs35l41_hda creates ALSA controls whose private data points at the cs35l41_hda object.
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices ad_sigma_delta_clear_pending_event() falls through to the status register read path for devices with has_registers = false and no rdy_gpiod.