CRITICAL 7 min read 31 Jul 2026

CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity Leads Today's Security Review

Executive assessment Today's brief leads with CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity. All 12 selected findings retain their own technical scope, action, observed status, and evidence limits.

Key findings
01
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
CRITICAL
The cited advisory discloses: CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity. CVE coverage: CVE-2026-63077.
02
Multiple vulnerabilities in Phoenix Contact CHARX
CRITICAL
The cited advisories disclose: SEC-3150 Missing Cryptographic Signature Remote Code Execution Vulnerability; SEC-3150 Jupicore External Control of Path Remote Code Execution Vulnerability; SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability; SEC-3150
03
Still active: Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
CRITICAL
First reported 2026-07-30; ongoing coverage. The cited advisory discloses: Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw. CVE coverage: CVE-2026-16812.
04
Still active: Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
CRITICAL
First reported 2026-07-30; ongoing coverage. The cited advisory discloses: Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory. CVE coverage: CVE-2026-59726.
05
ZDI-26-521: Phoenix Contact CHARX SEC-3000 Command Injection Remote Code Execution Vulnerability…
HIGH
The cited advisory discloses: ZDI-26-521: Phoenix Contact CHARX SEC-3000 Command Injection Remote Code Execution Vulnerability. CVE coverage: CVE-2026-44095.
06
Still active: Multiple vulnerabilities in WatchGuard FireWare OS
HIGH
First reported 2026-07-30; ongoing coverage. The cited advisories disclose: cli Token Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability; sigd compstartcb Directory Traversal Arbitrary File Creation Vulnerability. CVE coverage: CVE-2026-13053, CVE-2026-13054.
07
Still active: ZDI-26-500: WatchGuard FireWare OS networkd networkwirelesskickoffuser_cb Stack-based Buffer Overflow Remote Code Execution Vulnerabilit
HIGH
First reported 2026-07-30; ongoing coverage. The cited advisory discloses: ZDI-26-500: WatchGuard FireWare OS networkd networkwirelesskickoffuser_cb Stack-based Buffer Overflow Remote Code Execution Vulnerability. CVE coverage: CVE-2026-13050.
08
Still active: GHSA-wchh-9x6h-7f6p: olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
HIGH
First reported 2026-07-30; ongoing coverage. The cited advisory discloses: GHSA-wchh-9x6h-7f6p: olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193. CVE coverage: CVE-2022-39255, CVE-2024-45193.
09
Still active: Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
MEDIUM
First reported 2026-07-30; ongoing coverage. The cited advisory discloses: Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser. CVE coverage: CVE-2026-10702.
10
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
INFO
The cited advisory discloses: Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation. CVE coverage: none.
11
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
INFO
The cited advisory discloses: Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents. CVE coverage: none.
12
Still active: Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
INFO
First reported 2026-07-29; ongoing coverage. The cited advisory discloses: Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock. CVE coverage: none.

Executive assessment

Today's brief leads with CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity. All 12 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

What changed: The cited advisory discloses: CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity. CVE coverage: CVE-2026-63077.

Technical evidence: CVE-2026-63077; CVSS v3.1 9.8; weakness ['CWE-502']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-63077 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.rapid7.com](<https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity>)

Finding 02 — Multiple vulnerabilities in Phoenix Contact CHARX

What changed: The cited advisories disclose: SEC-3150 Missing Cryptographic Signature Remote Code Execution Vulnerability; SEC-3150 Jupicore External Control of Path Remote Code Execution Vulnerability; SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability; SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability; SEC-3150 BackendURL WebSocket Command Injection Remote Code Execution Vulnerability; SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability; SEC-3150 MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability; SEC-3150 Privilege Defined With Unsafe Actions Local Privilege Escalation Vulnerability; SEC-3150 update2-upload Arbitrary File Upload Vulnerability; SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability; SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability; SEC-3150 Failing Open Authentication Bypass Vulnerability; SEC-3150 user-applications Symlink Following Local Privilege Escalation Vulnerability; SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability; SEC-3150 charx-system-config-manager Service CRLF Injection Firewall Bypass Vulnerability; SEC-3150 Insertion of Sensitive Information into Log File Authentication Bypass Vulnerability; SEC-3150 Race Condition Firewall Bypass Vulnerability; SEC-3150 user-applications Link Following Local Privilege Escalation Vulnerability; SEC-3150 charx-jupicore Missing Authentication Configuration Modification Vulnerability. CVE coverage: CVE-2026-44104, CVE-2026-44103, CVE-2026-44101, CVE-2026-44099, CVE-2026-44098, CVE-2026-7849, CVE-2026-44091, CVE-2026-44096, CVE-2026-44097, CVE-2026-41032, CVE-2026-44107, CVE-2026-44094, CVE-2026-44093, CVE-2026-44090, CVE-2026-44092, CVE-2026-44105, CVE-2026-44108, CVE-2026-44106, CVE-2026-44100.

Technical evidence: CVE-2026-44104; CVSS v4.0 9.3; weakness ['CWE-347']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-44104 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-510/>)

Finding 03 — Still active: Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

Coverage status: First reported 2026-07-30; ongoing coverage.

What changed: The cited advisory discloses: Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw. CVE coverage: CVE-2026-16812.

Technical evidence: CVE-2026-16812; CVSS v3.1 10; weakness ['CWE-78']; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Action: Map CVE-2026-16812 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html>)

Finding 04 — Still active: Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Coverage status: First reported 2026-07-30; ongoing coverage.

What changed: The cited advisory discloses: Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory. CVE coverage: CVE-2026-59726.

Technical evidence: CVE-2026-59726; CVSS v3.1 10; weakness ['CWE-78', 'CWE-306', 'CWE-942']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-59726 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html>)

Finding 05 — ZDI-26-521: Phoenix Contact CHARX SEC-3000 Command Injection Remote Code Execution Vulnerability…

What changed: The cited advisory discloses: ZDI-26-521: Phoenix Contact CHARX SEC-3000 Command Injection Remote Code Execution Vulnerability. CVE coverage: CVE-2026-44095.

Technical evidence: CVE-2026-44095; CVSS v4.0 8.5; weakness ['CWE-78']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-44095 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-521/>)

Finding 06 — Still active: Multiple vulnerabilities in WatchGuard FireWare OS

Coverage status: First reported 2026-07-30; ongoing coverage.

What changed: The cited advisories disclose: cli Token Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability; sigd compstartcb Directory Traversal Arbitrary File Creation Vulnerability. CVE coverage: CVE-2026-13053, CVE-2026-13054.

Technical evidence: CVE-2026-13053; CVSS v4.0 8.6; weakness ['CWE-787']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-13053 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-499/>)

Finding 07 — Still active: ZDI-26-500: WatchGuard FireWare OS networkd networkwirelesskickoffusercb Stack-based Buffer Overflow Remote Code Execution Vulnerability…

Coverage status: First reported 2026-07-30; ongoing coverage.

What changed: The cited advisory discloses: ZDI-26-500: WatchGuard FireWare OS networkd networkwirelesskickoffusercb Stack-based Buffer Overflow Remote Code Execution Vulnerability. CVE coverage: CVE-2026-13050.

Technical evidence: CVE-2026-13050; CVSS v4.0 8.6; weakness ['CWE-787']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-13050 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-500/>)

Finding 08 — Still active: GHSA-wchh-9x6h-7f6p: olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193

Coverage status: First reported 2026-07-30; ongoing coverage.

What changed: The cited advisory discloses: GHSA-wchh-9x6h-7f6p: olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193. CVE coverage: CVE-2022-39255, CVE-2024-45193.

Technical evidence: CVE-2022-39255; CVSS v3.1 8.6; weakness ['CWE-322', 'CWE-287']; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2022-39255 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-wchh-9x6h-7f6p>)

Finding 09 — Still active: Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

Coverage status: First reported 2026-07-30; ongoing coverage.

What changed: The cited advisory discloses: Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser. CVE coverage: CVE-2026-10702.

Technical evidence: CVE-2026-10702; CVSS v3.1 4.3; weakness ['CWE-843']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-10702 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/researchers-show-single-malicious.html>)

Finding 10 — Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

What changed: The cited advisory discloses: Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation. CVE coverage: none.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html>)

Finding 11 — Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

What changed: The cited advisory discloses: Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents. CVE coverage: none.

Why it matters: Public exploit code is available, so weaponisation is low-effort; prioritise exposure validation and patching ahead of routine cycles.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html>)

Finding 12 — Still active: Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock

Coverage status: First reported 2026-07-29; ongoing coverage.

What changed: The cited advisory discloses: Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock. CVE coverage: none.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.theregister.com](<https://www.theregister.com/security/2026/07/28/arista-patches-actively-exploited-velocloud-bug-as-cisa-puts-admins-on-the-clock/5279414>)

cve-2022-39255cve-2026-10702cve-2026-13050cve-2026-13053cve-2026-16812cve-2026-44095cve-2026-59726cve-2026-63077

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.