CVE-2026-106218: JetBrains TeamCity

Critical severity, CVSS 10.0. EPSS: 0.3% chance of exploitation in the next 30 days.

In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible

Affected products

  • JetBrains TeamCity: before 2025.11.7 (fixed in 2025.11.7); from 2026.1.1, before 2026.1.3 (fixed in 2026.1.3)

Published 2026-10-06. Last modified 2026-10-08.