Unauthenticated remote code execution in TeamCity via malformed HTTP requests to the agent polling protocol requires immediate patching or plugin installation.
The Rails security vulnerability CVE-2026-66066 with CVSS score 9.5 allows unauthenticated attackers to read sensitive data such as secrets and database credentials via Active Storage.
CVE-2026-50751 (CVSS 9.3) enables circumvention of user authentication in Check Point VPN deployments with IKEv1 through a certificate validation flaw.