Unauthenticated remote code execution in TeamCity via malformed HTTP requests to the agent polling protocol requires immediate patching or plugin installation.
Check Point has patched a critical authentication vulnerability (CVE-2026-16232) in SmartConsole that is already being exploited and allows full admin access.
The SimpleHelp vulnerability CVE-2024-48558 is being exploited to distribute the Djinn infostealer in order to steal cloud and AI credentials and gain access to critical enterprise resources.
The Sentry vulnerabilities CVE-2026-10523 and CVE-2026-10520 enable unauthenticated attackers to bypass authentication and achieve Remote Code Execution with root privileges, requiring immediate patching to versions 10.5.2, 10.6.2, or 10.7.1.