ProjectDiscovery added a Nuclei template for CVE-2024-27198, an authentication bypass affecting JetBrains TeamCity versions earlier than 2023.11.4. The template is intended to help defenders identify exposed TeamCity servers vulnerable to unauthorized access, a flaw that drew broad attention because it can allow attackers to reach administrative functionality without valid credentials.
The related references also show ongoing community work to operationalize and remediate disclosed vulnerabilities across the ecosystem, including a GitHub pull request to fix a path traversal issue in BeehiveInnovations' pal-mcp-server, a Nuclei template contribution for CVE-2023-40044, and Google security research updates for kernelCTF CVE-2024-50264. Together, the activity reflects active publication of detection content, exploit research, and code fixes for high-impact flaws spanning enterprise software, open-source applications, and the Linux kernel.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
BeehiveInnovations opened pull request #353 to fix a path traversal vulnerability in the pal-mcp-server function is_dangerous_path(). The change reflects a remediation step for the identified flaw.
Google's security-research repository published a pull request adding a kernelCTF entry for CVE-2024-50264_lts_cos. This marks public technical documentation or research material related to the kernel vulnerability.
A ProjectDiscovery nuclei template pull request was opened to detect CVE-2024-27198, an authentication bypass affecting TeamCity versions earlier than 2023.11.4. This indicates public technical detection content for the vulnerability became available.
A ProjectDiscovery nuclei-templates pull request was published to add detection coverage for CVE-2023-40044. This represents public release of scanning logic for the vulnerability.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.