MilikMilik

Two Critical Vulnerabilities Put Core Enterprise Systems at Risk

Two Critical Vulnerabilities Put Core Enterprise Systems at Risk
Interest|High-Quality Software

Critical software vulnerabilities that open your front and back doors

Critical software vulnerabilities in perimeter VPNs and CI/CD platforms are security flaws that allow remote attackers to bypass authentication or run code on core enterprise infrastructure, turning everyday administration tools into reliable entry points for data theft, ransomware deployment, and long-term network compromise. Two active security issues should now dominate every enterprise security advisory update: a Palo Alto VPN exploit in GlobalProtect and the new TeamCity RCE vulnerability in JetBrains’ on‑premises CI/CD servers. The first issue affects your perimeter gateway, the second your build and deployment pipeline; together they represent the shortest path for adversaries from the internet into production. If you are responsible for enterprise security patches, treating these as routine is a mistake. They demand emergency-change mindset, not “next maintenance window” scheduling.

Palo Alto GlobalProtect: when your VPN becomes the master key

The Palo Alto Networks GlobalProtect flaw, tracked as CVE-2026-0257, allows attackers to bypass authentication and establish an unauthorized VPN connection to your environment. This vulnerability hits the GlobalProtect portal and gateway components of PAN‑OS, and its CVSS score has been upgraded to 7.8, moving it from a medium to a high‑severity issue. That change is not academic: the vendor raised the rating after learning it was being exploited in the wild. Managed detection teams have already observed successful exploitation attempts against multiple customers, even though they did not yet see lateral movement from compromised devices. Ransomware operators, including the Qilin group or its affiliates, are suspected in some of these GlobalProtect attacks. When your VPN authentication can be bypassed, attackers are not “at the door”—they are through it.

If your organization still treats VPN and firewall patching as a slow, risk-averse process, this is your wake‑up call. Perimeter defences are now priority targets for ransomware gangs and other threat actors, because compromising them yields authenticated access without noisy credential stuffing or phishing campaigns. Leaving GlobalProtect exposed and unpatched is equivalent to leaving a privileged local admin account with a weak password on an internet‑facing server. The lesson is clear: any medium‑rated bug in perimeter software can be re‑evaluated overnight once field exploitation appears, and your patching strategy must be able to respond at that speed.

TeamCity RCE: a single bug that can poison your entire pipeline

While the VPN issue threatens the front door, JetBrains TeamCity On‑Premises faces a critical back‑end problem: CVE-2026-63077, a TeamCity RCE vulnerability that affects all on‑premises versions. The flaw is exploitable via the TeamCity agent polling protocol and allows attackers to bypass authentication checks and execute OS commands with the privileges of the TeamCity server process. Depending on those privileges, a successful attack can expose configuration and stored credentials, modify server state, and even compromise the integrity of build artifacts and downstream CI/CD pipelines. State‑sponsored groups and ransomware affiliates have historically exploited unpatched TeamCity On‑Premises servers, so treating this as a speculative risk is dangerous.

The uncomfortable truth is that CI/CD platforms have become one of the most valuable targets in the enterprise. They hold secrets, control deployments, and sit at the junction between development and production. Attackers who gain TeamCity server‑level code execution can poison builds, introduce backdoors into signed software, and then ride your update pipeline into every environment that trusts your artifacts. The only reason we are not yet seeing mass exploitation reports for CVE-2026-63077 is timing, not lack of interest; the vendor has stated that, at advisory time, they were not aware of active exploitation. Waiting for that to change is a reckless strategy.

Two Critical Vulnerabilities Put Core Enterprise Systems at Risk

What enterprise admins must do today

On the GlobalProtect side, your first action is simple: apply the vendor’s enterprise security patches for all affected PAN‑OS appliances immediately. At the same time, disable GlobalProtect authentication override cookies and related features, since exploited environments often had these enabled. If Cloud Authentication Service is disabled, treat that as another risk flag and review whether your configuration is increasing exposure. After patching, comb VPN logs for suspicious new connections or anomalous authentication patterns around the known exploitation window and beyond. Assume that if your perimeter was exposed and unpatched during the exploitation period, it warrants a targeted threat‑hunting exercise, not a box‑checking audit.

For TeamCity On‑Premises, the minimum response is to upgrade to version 2025.11.7 or 2026.1.3, or, if that is not yet possible, install the security patch plugin on any instance from v2017.1 onwards. Older installations from v2017.1 to v2018.1 require a server restart after patching, while later versions allow enabling the plugin without reboot. Beyond patching, tighten network exposure: limit access to trusted networks or require VPN access or an additional security layer before anyone can reach your TeamCity login or REST API. The vendor specifically warns that even exposing those interfaces can give attackers an entry point for newly disclosed vulnerabilities. Finally, run the TeamCity server with the minimum OS privileges necessary, so that any future exploit has less room to damage.

Shift your patching culture before attackers shift your priorities for you

The connecting thread between the Palo Alto VPN exploit and the TeamCity RCE vulnerability is not only their technical impact but what they reveal about current attacker strategy. VPNs, firewalls, and CI/CD servers are no longer “supporting” systems; they are primary targets for initial access, ransomware deployment, and long‑term supply‑chain campaigns. Treating these platforms as boring plumbing that can wait for the next quarterly change window is incompatible with the threat landscape. If your organization wants to stay ahead, you need a patching process that can push emergency fixes for perimeter and pipeline software in days, not weeks, coupled with configuration hardening that minimizes public exposure. The choice is stark: either you move fast to apply critical software vulnerabilities and tighten access, or attackers will move faster to turn your infrastructure against you.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!