PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-65906 JetBrains CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T13:16:31.733Z and has not been modified since then. This vulnerability affects JetBrains TeamCity versions before 2026.1.2 or 2025.11.6, allowing for code execution via Kotlin DSL sandbox escape. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. Administrators and users should be aware of this vulnerability and take necessary actions to mitigate it.

Vendor
JetBrains
Product
TeamCity
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-23
Original CVE updated
2026-08-11
Advisory published
2026-07-23
Advisory updated
2026-08-11

Who should care

Administrators and users of JetBrains TeamCity, especially those with versions before 2026.1.2 or 2025.11.6, should be aware of this vulnerability and take necessary actions to mitigate it. This includes verifying affected deployments, applying vendor-provided patches or updates, and monitoring TeamCity systems for suspicious activity.

Technical summary

A vulnerability in JetBrains TeamCity before 2026.1.2 and 2025.11.6 allows for code execution via Kotlin DSL sandbox escape. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. This issue affects administrators and users of JetBrains TeamCity, especially those with versions before 2026.1.2 or 2025.11.6.

Defensive priority

High priority due to the HIGH CVSS score of 8.8 and the possibility of code execution via Kotlin DSL sandbox escape.

Recommended defensive actions

  • Inventory and verify TeamCity versions, checking for versions before 2026.1.2 or 2025.11.6
  • Apply vendor-provided patches or updates to mitigate the vulnerability
  • Monitor TeamCity systems for suspicious activity
  • Implement compensating controls, such as network segmentation or access restrictions
  • Review and update incident response plans to address potential code execution attacks

Evidence notes

Evidence from official sources indicates a vulnerability in JetBrains TeamCity before 2026.1.2 and 2025.11.6, allowing for code execution via Kotlin DSL sandbox escape. Limited details are available on the exact scope of affected systems and potential attack vectors. The CVE record was published on 2026-07-23T13:16:31.733Z and has not been modified since then. Further verification is recommended to confirm affected deployments and assess potential impact.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T13:16:31.733Z and has not been modified since then.