Friday’s brief: TeamCity ransomware, then Roundcube, cPanel, GitLab

By George Bailey   Published: 09/25/26   2 min read

Published: 09/25/26

Friday’s brief starts where your software starts: the build server. CISA now links ransomware to a TeamCity hole patched in July. Also on the desk — a Roundcube webmail bug that’s now being exploited, a cPanel flaw that turns any hosting account into root, and a GitLab “email an issue” address that can quietly push code.

Lead Story

Ransomware crews now target TeamCity — patch your build server

CVE-2026-63077 lets an unauthenticated attacker run OS commands on TeamCity On-Premises through the agent polling protocol. JetBrains fixed it in 2025.11.7 and 2026.1.3 in July; on September 23 CISA flagged it as used in ransomware campaigns. Just over 160 exposed servers are still unpatched.

Why it matters: Own the build server and you own every release — plus the credentials it stores.

Check your build server →

Also Worth Your Attention

An old Roundcube webmail bug is now exploited

CVE-2026-48842, a pre-auth SQL injection in the virtuser_query plugin (patched May 24), is now exploited, per the Canadian Centre for Cyber Security. Upgrade to 1.6.16 or 1.7.1, or disable the plugin.

Why it matters: 523,000+ Roundcube instances face the Internet, and it ships with cPanel.

Kill the plugin or patch →

One cPanel customer can own the whole server

CVE-2026-87899 in cPanel’s CalDAV/CardDAV service lets any logged-in account holder run code as root. A WP Toolkit bug (CVE-2026-87900) crosses account lines too. Update to 11.134.0.57 / 11.136.0.41 / 11.138.0.8 and WP Toolkit 6.11.3.

Why it matters: On shared hosting, your neighbor’s login can become the whole server. No workaround.

Questions for your host →

Your GitLab “issue email” address can push code

Aikido showed the private incoming-email address embeds an account-wide, non-expiring token. Anyone holding it can commit to branches and run CI as you — even past IP allowlists. No CVE; GitLab calls it intended behavior.

Why it matters: Some teams publish that address in their README on purpose.

Rotate the token →

Slack paste: TeamCity patched + off the Internet; Roundcube 1.6.16/1.7.1 or no virtuser_query; cPanel + WP Toolkit updated; GitLab Maintainers reset Incoming email token.

Go Deeper

Identity & access: IAM library · Tools & playbooks: Cybersecurity Tools · Subscribe: Daily Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.