Unauthenticated remote code execution in TeamCity via malformed HTTP requests to the agent polling protocol requires immediate patching or plugin installation.
IBM WebSphere Application Server and Liberty contain multiple vulnerabilities that enable arbitrary code execution with server privileges, data disclosure, and privilege escalation.
Attackers with repository write permissions can execute shell commands as the Gitea service account in versions 1.17–1.27.0 via Git Hooks; fix available in 1.27.1.
SAP released patches in July 2026 against vulnerabilities that enable arbitrary code execution, SQL injection, cross-site scripting, file manipulation, information disclosure, and circumvention of security controls.
Critical unauthenticated command injection in Arista VeloCloud Orchestrator On-Premises is actively exploited; CISA orders remediation by 30 July 2026.
Critical CVE-2026-16812 in Arista VeloCloud Orchestrator On-Premises with CVSS 10.0 is being actively exploited by attackers for remote code execution.