Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
2026-08-08T19:23:37Z•ed79b98192a896f88e4eb79cf9e56f7b16dec5af2806a82c7ce515d0426e9ff3
CVE-2026-18556CVE-2026-18577CVE-2026-63077CVE-2026-66066Active StorageJetBrains TeamCityKEVMetasploitN-able N-centralRuby on Railsarbitrary-file-readauthentication-bypasscriticalexploitation-in-the-wildlibvipsremote-code-executionsecurity-newsunauthenticated-RCEvulnerability
What happened
Rapid7 reporting highlights multiple critical vulnerabilities disclosed or exploited in August 2026, including unauthenticated remote code execution in JetBrains TeamCity (CVE-2026-63077), an authentication bypass in N-able N-central (CVE-2026-18577) exploited in the wild, and critical arbitrary file read with possible RCE in Ruby on Rails Active Storage using libvips (CVE-2026-66066). The feed also includes Metasploit Pro 5.1 capabilities and non-security corporate and conference announcements.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- ed79b98192a896f88e4eb79cf9e56f7b16dec5af2806a82c7ce515d0426e9ff3
- Enrichment time
- 2026-08-08T19:23:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.