<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — JetBrains</title><description>Vulnerabilities in JetBrains TeamCity, YouTrack, and other build/collaboration servers — CI/CD infrastructure whose compromise puts the entire downstream software supply chain at risk of build poisoning and artifact tampering. Combined article + CVE feed for the JetBrains beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>JetBrains Cadence Breached via Unpatched TeamCity RCE</title><link>https://0daynews.com/articles/2026-09-06-jetbrains-cadence-teamcity-cve-2026-63077-breach/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-09-06-jetbrains-cadence-teamcity-cve-2026-63077-breach/</guid><description>AWS keys, source code, and a server backup stolen from JetBrains Cadence after its TeamCity server went unpatched for weeks against CVE-2026-63077.</description><pubDate>Sun, 06 Sep 2026 06:00:00 GMT</pubDate><category>JetBrains</category><category>article</category></item><item><title>CVE-2023-42793 — JetBrains TeamCity Authentication Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2023-42793/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-42793/</guid><description>JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.</description><pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate><category>JetBrains</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-27198 — JetBrains TeamCity Authentication Bypass</title><link>https://0daynews.com/cve/cve-2024-27198/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-27198/</guid><description>An authentication-bypass vulnerability in JetBrains TeamCity&apos;s web component allows a remote, unauthenticated attacker to perform admin actions on the CI/CD server, enabling full takeover of build pipelines.</description><pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate><category>JetBrains</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-27199 — JetBrains TeamCity Relative Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2024-27199/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-27199/</guid><description>JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.</description><pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate><category>JetBrains</category><category>high</category><category>cve</category></item><item><title>CVE-2026-63077 — JetBrains TeamCity On-Prem Unauthenticated RCE</title><link>https://0daynews.com/cve/cve-2026-63077/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-63077/</guid><description>CVSS 9.8 critical. Unauthenticated remote code execution in all JetBrains TeamCity On-Premises versions, fixed in 2025.11.7 and 2026.1.3.</description><pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate><category>JetBrains</category><category>critical</category><category>cve</category></item><item><title>TeamCity CVE-2026-63077: Agent Protocol Is the Vector</title><link>https://0daynews.com/articles/2026-07-29-teamcity-cve-2026-63077-rapid7-agent-protocol/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-29-teamcity-cve-2026-63077-rapid7-agent-protocol/</guid><description>Rapid7&apos;s ETR confirms CVE-2026-63077 sits in TeamCity&apos;s agent polling protocol — deserialization, no credentials needed. Patch to 2025.11.7 or 2026.1.3.</description><pubDate>Wed, 29 Jul 2026 23:00:00 GMT</pubDate><category>JetBrains</category><category>article</category></item><item><title>TeamCity 9.8 RCE Flaw Hits All On-Prem Versions</title><link>https://0daynews.com/articles/2026-07-28-teamcity-cve-2026-63077-rce-all-onprem/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-28-teamcity-cve-2026-63077-rce-all-onprem/</guid><description>JetBrains has patched CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in all TeamCity On-Premises versions. Update to 2025.11.7 or 2026.1.3 now.</description><pubDate>Tue, 28 Jul 2026 10:00:00 GMT</pubDate><category>JetBrains</category><category>article</category></item><item><title>TeamCity CVE-2024-27198: EPSS 0.999 two years past patch</title><link>https://0daynews.com/articles/2026-07-21-jetbrains-teamcity-cve-2024-27198-epss-0999-two-years-past-patch/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-jetbrains-teamcity-cve-2024-27198-epss-0999-two-years-past-patch/</guid><description>JetBrains TeamCity&apos;s 2024 auth-bypass still ranks EPSS 0.999 more than two years post patch. Internet-facing build servers keep the exposed population alive.</description><pubDate>Tue, 21 Jul 2026 07:05:00 GMT</pubDate><category>JetBrains</category><category>article</category></item></channel></rss>