Published: 09/25/26
Friday’s brief starts where your software starts: the build server. CISA now links ransomware to a TeamCity hole patched in July. Also on the desk — a Roundcube webmail bug that’s now being exploited, a cPanel flaw that turns any hosting account into root, and a GitLab “email an issue” address that can quietly push code.
Lead Story
Ransomware crews now target TeamCity — patch your build server
CVE-2026-63077 lets an unauthenticated attacker run OS commands on TeamCity On-Premises through the agent polling protocol. JetBrains fixed it in 2025.11.7 and 2026.1.3 in July; on September 23 CISA flagged it as used in ransomware campaigns. Just over 160 exposed servers are still unpatched.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: Own the build server and you own every release — plus the credentials it stores.
Also Worth Your Attention
An old Roundcube webmail bug is now exploited
CVE-2026-48842, a pre-auth SQL injection in the virtuser_query plugin (patched May 24), is now exploited, per the Canadian Centre for Cyber Security. Upgrade to 1.6.16 or 1.7.1, or disable the plugin.
Why it matters: 523,000+ Roundcube instances face the Internet, and it ships with cPanel.
One cPanel customer can own the whole server
CVE-2026-87899 in cPanel’s CalDAV/CardDAV service lets any logged-in account holder run code as root. A WP Toolkit bug (CVE-2026-87900) crosses account lines too. Update to 11.134.0.57 / 11.136.0.41 / 11.138.0.8 and WP Toolkit 6.11.3.
Why it matters: On shared hosting, your neighbor’s login can become the whole server. No workaround.
Your GitLab “issue email” address can push code
Aikido showed the private incoming-email address embeds an account-wide, non-expiring token. Anyone holding it can commit to branches and run CI as you — even past IP allowlists. No CVE; GitLab calls it intended behavior.
Why it matters: Some teams publish that address in their README on purpose.
Slack paste: TeamCity patched + off the Internet; Roundcube 1.6.16/1.7.1 or no virtuser_query; cPanel + WP Toolkit updated; GitLab Maintainers reset Incoming email token.
Go Deeper
Identity & access: IAM library · Tools & playbooks: Cybersecurity Tools · Subscribe: Daily Brief
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.