CVE-2026-106218: JetBrains TeamCity
Critical severity, CVSS 10.0. EPSS: 0.3% chance of exploitation in the next 30 days.
In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible
Affected products
- JetBrains TeamCity: before 2025.11.7 (fixed in 2025.11.7); from 2026.1.1, before 2026.1.3 (fixed in 2026.1.3)
Published 2026-10-06. Last modified 2026-10-08.