Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability

Threat actors have started exploiting a recently patched vulnerability in JetBrains TeamCity, the US cybersecurity agency CISA warns.
A continuous integration and continuous delivery (CI/CD) platform, TeamCity provides automated software building and deployment and is a central component of enterprise workflows, collaboration, and development practices.
Tracked as CVE-2026-63077 (CVSS score of 9.8), the critical security defect is related to deserialization of untrusted data and allows unauthenticated attackers to achieve remote code execution (RCE) via HTTP/S requests.
Impacting all TeamCity On-Premises versions, the flaw enables attackers to “bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,” JetBrains warned last week.
Patches for the issue were included in TeamCity versions 2025.11.7 and 2026.1.3. A security patch plugin for version 2017.1+ was also released.
“An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol,” JetBrains said, urging organizations to apply the patches to their TeamCity On-Premises deployments as soon as possible.
In its advisory, JetBrains noted that the security defect was reported privately and that it was not aware of any active exploitation.
On Wednesday, roughly a week after public disclosure, CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, as mandated by BOD 26-04.
There does not appear to be any public information on the attacks exploiting the vulnerability.
Related: How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
Related: New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Related: CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
Related: Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
https://www.securityweek.com/hackers-start-exploiting-recent-jetbrains-teamcity-vulnerability/