Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3340 articles · 182819 vulns · 36/41 feeds (7d)
← Back to list
9.1
CVE-2026-65907PATCHED
jetbrains · teamcity

CVE-2026-65907: In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible

Description

In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible

Affected Products

VendorProductVersions
jetbrainsteamcity0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
jetbrainsteamcitycert_advisory90%

References

  • https://www.jetbrains.com/privacy-security/issues-fixed/

Related News (2 articles)

Tier B
BSI Advisories7d ago
[NEU] [hoch] JetBrains TeamCity: Mehrere Schwachstellen ermöglichen Codeausführung
→ No new info (linked only)
Tier C
VulDB8d ago
CVE-2026-65907 | JetBrains TeamCity prior 2026.1.2/2025.11.6 Git VCS Roots code injection
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.1.22025.11.6
CWECWE-94
PublishedJul 23, 2026
Trending Score19
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-63077
CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
Trending: 80
CRITICALCVE-2026-64812
CVE-2026-64812: In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
Trending: 24
CRITICALCVE-2026-64813
CVE-2026-64813: In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
Trending: 24
HIGHCVE-2026-64814
CVE-2026-64814: In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
Trending: 20
HIGHCVE-2026-64807
CVE-2026-64807: In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
Trending: 17

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 23, 2026
Discovered by ZDM
Jul 23, 2026
Patch Available
Jul 24, 2026