CVE-2026-63077
Published Jul 27, 2026
Last updated 2 months ago
AI description
CVE-2026-63077 is an unauthenticated remote code execution vulnerability affecting JetBrains TeamCity On-Premises versions prior to 2026.1.3 and 2025.11.7. This flaw, categorized as a deserialization of untrusted data (CWE-502), resides within the TeamCity agent polling protocol. An attacker with network access to the TeamCity server can exploit this vulnerability to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. The root cause involves an issue with the XStream class type permission reset, which results in an overly permissive allowlist for deserialization.
- Description
- In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
- Source
- cve@jetbrains.com
- NVD status
- Analyzed
- Products
- teamcity
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
- Exploit added on
- Aug 5, 2026
- Exploit action due
- Aug 8, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- cve@jetbrains.com
- CWE-502
- Hype score
- Not currently trending
Ransomware groups are actively exploiting JetBrains TeamCity CVE-2026-63077 (CVSS 9.8 RCE). Patch exposed servers, rotate build secrets, and audit pipeline logs. Intel: https://t.co/QC14eBVf0C Source: https://t.co/flbxRbkBgY #2workly #CTI
@2Workly
25 Sept 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA now flags ransomware gangs exploiting TeamCity CVE-2026-63077. Unauth RCE via agent polling; ~160 servers still exposed (Shadowserver). Via BleepingComputer. Verify independently. #CyberSecurity #InfoSec #Ransomware #CVE #ThreatIntel
@ThreatAlis
25 Sept 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Ransomware gangs exploited CVE-2026-63077 to bypass TeamCity authentication and execute OS commands without credentials. Attackers leveraged CI/CD access to compromise build artifacts and move laterally through connected environments. Runtime segmentation helps contain
@aviatrixtrc
25 Sept 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
𝗔𝘁𝘁𝗮𝗰𝗸𝗲𝗿𝘀 𝗕𝗿𝗲𝗮𝗰𝗵𝗲𝗱 𝗝𝗲𝘁𝗕𝗿𝗮𝗶𝗻𝘀 𝗖𝗮𝗱𝗲𝗻𝗰𝗲 𝘃𝗶𝗮 𝗨𝗻𝗽𝗮𝘁𝗰𝗵𝗲𝗱 𝗧𝗲𝗮𝗺𝗖𝗶𝘁𝘆, 𝗘𝘅𝘁𝗿𝗮𝗰𝘁𝗶𝗻𝗴 𝗔𝗪𝗦 𝗖
@ShadowSpanHQ
13 Sept 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JetBrains'in Cadence Bulut Hizmeti, Yamalanmamış TeamCity Üzerinden İhlal Edildi; AWS Kimlik Bilgileri Çalındı! Saldırganlar, JetBrains'in TeamCity sürekli entegrasyon sunucusundaki CVE-2026-63077 (CVSS 9.8) deserialization açığını istismar ederek şirketin Cadence
@BTHaberler
9 Sept 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
They published the TeamCity RCE advisory. their own Cadence box was still on the vulnerable build. JetBrains told everyone to patch CVE-2026-63077 in July. Cadence, their own hosted compute path behind PyCharm, was still sitting on an unpatched TeamCity server. Attackers were
@ParmarUjjaval3
8 Sept 2026
54 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
They published the TeamCity RCE advisory. their own Cadence box was still on the vulnerable build. JetBrains told everyone to patch CVE-2026-63077 in July. Cadence, their own hosted compute path behind PyCharm, was still sitting on an unpatched TeamCity server. Attackers were
@ParmarUjjaval3
8 Sept 2026
6 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
JetBrains shipped the TeamCity RCE advisory in July. Cadence, their own hosted service, stayed vulnerable. Attackers used CVE-2026-63077 Aug 8–24 and walked a 2024 backup plus AWS IAM. Rotate anything that touched Cadence. Hunt from Aug 8. JetBrains disclosed CVE-2026-63077 on
@BigVikDada
7 Sept 2026
47 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
"The server should have been patched as part of our response to the vulnerability, but it was not." That's JetBrains explaining how their own cloud service got breached. A critical TeamCity bug (CVE-2026-63077) let attackers into Cadence, JetBrains' PyCharm cloud service, for
@AzmyBlog
7 Sept 2026
53 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
JetBrains confirmed that attackers used CVE-2026-63077 against the TeamCity instance behind Cadence. The window was August 8 to 24. The company had already told customers to patch that bug. Its own Cadence server was not patched. What the actor obtained matters more than the CVE
@Breachrr
7 Sept 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 SUPPLY CHAIN ALERT: JetBrains Cadence Breached via Unpatched TeamCity Flaw (CVE-2026-63077) In what marks one of the most critical developer supply chain compromises this year, JetBrains confirmed that threat actors breached its cloud computing service, JetBrains Cadence,
@reach2ratan
6 Sept 2026
679 Impressions
14 Retweets
23 Likes
5 Bookmarks
2 Replies
0 Quotes
JetBrains patched the world, missed itselfCVE-2026-63077 (CVSS 9.8): unauthenticated OS command execution on TeamCity if you can hit HTTP/S. Disclosed Jul 27. Active exploit reports Aug 7. CISA KEV Aug 5.JetBrains Cadence used TeamCity. The Cadence box was not patched. Attack htt
@ichbinlucasv
6 Sept 2026
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
IOC (ipv4): 210[.]247[.]242[.]190 Campaign: JetBrains Cadence Breach: Exploitation of Unpatched TeamCity CVE-2026-63077 Context + related IOCs: https://t.co/WafKMWeEMt
@threatcluster
6 Sept 2026
57 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JetBrains says Cadence may have been breached via unpatched TeamCity CVE-2026-63077, exposing AWS credentials, backups, source code, and secrets. ##JetBrains #TeamCity #Cadence https://t.co/t2PHSjudXz
@TweetThreatNews
6 Sept 2026
217 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
❗ JetBrains’in Cadence Ortamı Hacklendi Saldırganlar, TeamCity’deki CVE-2026-63077 (CVSS 9.8) açığını kullanarak JetBrains’in Cadence ortamına sızdı. 2024 tarihli yedekten AWS kimlik bilgileri, kullanıcı verileri ve bazı proje kaynaklarına erişildiği doğ
@KubbeSiber
5 Sept 2026
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 JetBrains Cadence hackeado 🔓 Vulnerabilidad crítica CVE-2026-63077 en TeamCity expuso credenciales AWS de miles de desarrolladores entre el 8 y 24 de agosto. ⚠️ ¡Rotar YA todas las claves! https://t.co/Rleu03weWY
@renodevv
5 Sept 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JetBrains Cadence was compromised through TeamCity CVE-2026-63077. Confirmed path: Internet-facing TeamCity → unauthenticated RCE → Cadence server compromise → 2024 backup access → credential exposure → AWS IAM / S3 access The real question is what becomes reachable n
@vufaysecurity
1 Sept 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JetBrainsのCadence侵害は、脆弱性対応が「パッチを出した」で終わらないことをよく示している。 TeamCityのCVE-2026-63077は7月27日に公表され、修正版もあった。侵入は8月8日から。対象サーバーにはパッチが適用さ
@xyzmoatoganai
1 Sept 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 #CVE-2026-63077: Active Exploitation of TeamCity On-Premises RCE Vulnerability Demands Immediate Patching + Video -Prediction: 📈 3 Positive | 📉 4 Negative https://t.co/BEND6W4CRo Educational Purposes!
@UndercodeUpdate
1 Sept 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 [DEVELOPER SUPPLY-CHAIN BREACH] — ATTACKERS EXPLOITED JETBRAINS CADENCE THROUGH CVE-2026-63077, STOLE CUSTOMER DATA AND COMPROMISED AWS IAM CREDENTIALS JetBrains says the Cadence server SHOULD HAVE BEEN PATCHED — but wasn't. A 2024 full server backup was compromised,
@XQOPTRX
31 Aug 2026
131 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-63077: XStream Deserialization in JetBrains TeamCity’s Agent Polling Protocol Enables Pre-Auth RCE https://t.co/ihV3IEU5jj
@Dinosn
28 Aug 2026
3312 Impressions
6 Retweets
13 Likes
5 Bookmarks
0 Replies
0 Quotes
🚨 CONFIRMED EXPLOITATION — JETBRAINS CADENCE BREACHED THROUGH CRITICAL TEAMCITY FLAW JetBrains says attackers exploited CVE-2026-63077 against its own Cadence cloud environment — compromising a full server backup, AWS IAM credentials, personal data and potentially synchro
@XQOPTRX
28 Aug 2026
114 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ACSC has seen TeamCity On-Premises exploited here. CVE-2026-63077: unauth RCE over HTTP. Patch 2025.11.7 or 2026.1.3. https://t.co/lYed5AFnZc
@JustinMiddler
27 Aug 2026
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JetBrains TeamCity(オンプレミス版)におけるリモートコード実行につながる脆弱性(CVE-2026-63077)について #JPCERTCC (Aug 13) https://t.co/qF0EcnCjsT
@foxbook
16 Aug 2026
322 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Top #CVE to #patch this week 👀 - @VMware #ESXi 9.0 RCE (CVE-2026-47876, CVE-2026-41703) - @JetBrains #TeamCity RCE (CVE-2026-63077, CVE-2026-65907) - #Jenkins Core (CVE-2026-70426) - @zohocorp ManageEngine ADAudit RCE (CVE-2026-6516) - @IBM Langflow RCE (CVE-2026-9198) -
@stansecure
13 Aug 2026
51 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
More RCE this wk: - SharePoint auth-bypass+RCE chain, PoC public (CVE-2026-55040/63520) - TeamCity unauth RCE, now on CISA KEV (CVE-2026-63077) - DeadLock: new Rust ransomware, decentralized leak infra Patch SharePoint + TeamCity immediately. #ThreatIntel #Ransomware #CVE
@NoctisIntel
13 Aug 2026
91 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA added 3 NEW exploited CVEs this week. If your team runs any of these, patch today: • Progress LoadMaster (CVE-2026-8037, CVSS 9.8) • JetBrains TeamCity (CVE-2026-63077) • N-able N-central (CVE-2026-18577) https://t.co/JKBcwI6eWs
@FaultSignal_
10 Aug 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Vulnerabilities added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog with patch deadlines: 🔵 Progress LoadMaster (CVE-2026-8037): Command injection flaw → Due Aug 10, 2026 🔵 JetBrains TeamCity (CVE-2026-63077): Deserialization bug → Due Aug 8, 2026
@techepages
10 Aug 2026
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 IN THE WILD: CVE-2026-63077, a critical unauthenticated RCE in JetBrains TeamCity, is now being actively exploited. A public PoC is also available, significantly increasing the risk to unpatched servers. PoC: https://t.co/e0P7NE3kMJ #TeamCity #JetBrains #CVE #RCE
@ThreatWire_
10 Aug 2026
4569 Impressions
17 Retweets
48 Likes
20 Bookmarks
1 Reply
0 Quotes
🚨 CVE-2026-63077 - critical 🚨 JetBrains TeamCity < 2026.1.3, 2025.11.7 - Remote Code Execution > JetBrains TeamCity < 2026.1.3, 2025.11.7 contains a remote code execution caused by u... 👾 https://t.co/hMBXl18ntG @pdnuclei #NucleiTemplates #cve
@pdnuclei_bot
9 Aug 2026
1659 Impressions
7 Retweets
33 Likes
7 Bookmarks
0 Replies
0 Quotes
CISA and researchers flag active exploitation of critical flaws in JetBrains TeamCity (CVE-2026-63077) and N-able N-central (CVE-2026-18577). https://t.co/bFZxkFy4fP
@Cyb3rR3s34rch
8 Aug 2026
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-63077: JetBrains TeamCity Unauthenticated RCE in CISA KEV — Detection … "On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical…" 🔗 https://t.co/60xMZz8VBS #CyberSecurity #ThreatIntel #critical #zeroday #
@SecurityAr58409
8 Aug 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
𝗖𝗜𝗦𝗔 𝗙𝗹𝗮𝗴𝘀 𝗧𝗲𝗮𝗺𝗖𝗶𝘁𝘆 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟲𝟯𝟬𝟳𝟳 𝗥𝗖𝗘 𝗙𝗹𝗮𝘄 𝗨𝗻𝗱𝗲𝗿 𝗔𝗰𝘁𝗶𝘃𝗲 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝗮𝘁𝗶𝗼𝗻 𝗶𝗻 𝘁𝗵𝗲 𝗪𝗶
@ShadowSpanHQ
8 Aug 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Cyber Heat Radar|2026/08/08 05:00 JST 今回は①CVE-2026-63077 CISA KEV追加の件、②CVE-2026-8037 CISA KEV追加の件、③AI分散下のランサムウェア増加の件を中心に、音声で3件扱います。
@cyberheatradar
7 Aug 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-of-the-Day: CVE-2026-63077 — JetBrains TeamCity, unauthenticated RCE via the agent polling protocol The channel build agents use to pick up work deserializes untrusted data. Anyone who can reach that port runs code on your CI server. No login needed. #CVE #infosec http
@YourDailyCVE
7 Aug 2026
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
2 Replies
0 Quotes
Actively exploited JetBrains TeamCity RCE (CVE-2026-63077, Aug 5, 2026) allows unauth'd remote code execution. This critical flaw severely impacts backend data privacy & integrity. Patch now! #Cybersecurity #CVE #BackendSecurity
@YourAnon_irc
7 Aug 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-63077: JetBrains TeamCity Unauthenticated RCE Under Active Exploitatio… "Threat actors have begun actively exploiting CVE-2026-63077, a critical unauthenticated…" 🔗 https://t.co/f80d75qMxY #CyberSecurity #ThreatIntel #cve #zeroday #patchtue
@SecurityAr58409
7 Aug 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
パッチを当てる前に、すでに動いている——それが今日の4本の共通点だ。 CVSS 9.8超えが3本、CVSS 10.0が1本。CI/CDが突破され、VPNが破られ、100組織超に通知された。 「積極悪用中」はそういう意味だ。 ・TeamCity
@boss_sec_labo
6 Aug 2026
259 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-63077: JetBrains TeamCity Unauthenticated RCE Under Active Exploitatio… "CISA has added CVE-2026-63077 to its Known Exploited Vulnerabilities (KEV) catalog, confirming…" 🔗 https://t.co/XQw8shuWxy #CyberSecurity #ThreatIntel #critical #zerod
@SecurityAr58409
6 Aug 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ BOLLETTINO CYBER | 06/08/2026 1. Vulnerabilità critica in JetBrains TeamCity in sfruttamento attivo CSIRT Italia e CISA segnalano la CVE-2026-63077 (CVSS 9.8): RCE non autenticata su tutte le versioni on-premise di TeamCity tramite il protocollo agent polling. Aggiornar
@FrontieraTechIT
6 Aug 2026
94 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🔬 CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild Critical CVE / Exploit: A newly patched security flaw impacting on-premi... https://t.co/Yk2Xo8IhM5 #CVE #AI #CyberSecurity #DataProtection
@MyDooM15
6 Aug 2026
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-63077: JetBrains TeamCity Deserialization Bug Added to CISA KEV — Dete… "On August 5, 2026, CISA added CVE-2026-63077 — a deserialization of untrusted data…" 🔗 https://t.co/vHIj2hs8Wa #CyberSecurity #ThreatIntel #cve #zeroday #patchtues
@SecurityAr58409
6 Aug 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
JetBrains patched an unauth RCE in every TeamCity On-Premises version. CVE-2026-63077, CVSS 9.8. Deserialization in the agent polling protocol. HTTP access is the only precondition. No public PoC. Not in KEV. In 2024 that state lasted 48 hours. The runbook: https://t.co/V29QeH
@zerohuntai
1 Aug 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
JetBrains disclosed CVE-2026-63077, a critical auth bypass in TeamCity On-Premises that can lead to remote code execution over HTTPS. Fixed in 2025.11.7 and 2026.1.3. #JetBrains #TeamCity #CVE-2026-63077 https://t.co/Q6AvRoRZ9c
@TweetThreatNews
31 Jul 2026
258 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
🧠 Engineering & Research Digest (Jul 29) CVE-2026-63077--CVE-2026-63077: Critical unauthenticated: patch CVE-2026-63077: Critical unauthenticated immediately--RCE exposure. Full digest 👇--PCMedicalist Full digest 👇 via PCMedicalist #CyberSecurity #InfoSec #CompSci h
@PCMedicalist
30 Jul 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ BOLLETTINO CYBER | 29/07/2026 1. Vulnerabilità critica in JetBrains TeamCity (CVE-2026-63077) Rilevata una vulnerabilità critica di autenticazione bypass e remote code execution non autenticata. Un attaccante con accesso HTTP(S) al server può eseguire comandi arbitrar
@FrontieraTechIT
29 Jul 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
JetBrains社がTeamCityオンプレミス版における認証不要の重大なリモートコード実行(RCE)の脆弱性(CVE-2026-63077)を修正 JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) #HelpNetSecurity (Jul 28) https:
@foxbook
29 Jul 2026
304 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISO Daily Briefing: Arista VeloCloud Orchestrator zero-day (CVE-2026-16812, CVSS 10.0) is under active exploitation — CISA's KEV deadline is Thursday; also patch TeamCity's new unauthenticated RCE (CVE-2026-63077, CVSS 9.8) and the Certighost AD CS forgery bug (CVE-2026-54121)
@cloudsa
28 Jul 2026
440 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
#ExploitGrid Daily Threat Digest Top #Vulnerabilities (CVEs) of the day CVE-2026-16812 CVE-2026-12394 CVE-2026-13714 CVE-2026-63077 CVE-2026-66395 ..🧵👇
@exploitgrid
27 Jul 2026
46 Impressions
1 Retweet
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨*CVE* CVE-2026-63077 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol https://t.co/5hOZDYw139 ----- Traducción: CVE-2026-63077 En JetBrains TeamCity anterior a 2026.1.3… https://t.co/utmtNgl
@infoflowcloud
27 Jul 2026
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "4F865D53-6163-4A62-B8C1-06F45DA28E3C",
"versionEndExcluding": "2025.11.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "4CD39F06-B4AA-4300-B763-9362E98D50D6",
"versionEndExcluding": "2026.1.3",
"versionStartIncluding": "2026.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]