Hackers have begun taking advantage of a newly patched flaw in JetBrains TeamCity, according to an alert from the US Cybersecurity and Infrastructure Security Agency (CISA). This vulnerability, affecting the popular CI/CD platform, poses significant risks to enterprise software deployment and development processes.
Understanding the TeamCity Vulnerability
TeamCity, a widely used tool for continuous integration and delivery, has a critical security defect identified as CVE-2026-63077. This flaw, scoring 9.8 on the CVSS scale, involves the deserialization of untrusted data, allowing unauthorized attackers to perform remote code execution through HTTP/S requests.
The vulnerability impacts all On-Premises versions of TeamCity, enabling attackers to bypass security checks and execute arbitrary system commands with the same privileges as the TeamCity server. JetBrains highlighted the severity of this issue in a recent advisory, emphasizing the need for urgent action.
Patch Implementation and Recommendations
Patches addressing this critical defect are available in TeamCity versions 2025.11.7 and 2026.1.3. Additionally, a security patch plugin has been released for version 2017.1 and later. JetBrains strongly advises organizations to implement these patches immediately to safeguard their systems.
Despite the absence of active exploitation reports, JetBrains continues to stress the importance of updating vulnerable deployments. The flaw was privately reported, and the company’s advisory aims to raise awareness and prompt proactive measures against potential threats.
Regulatory Response and Implications
Following the public disclosure of the vulnerability, CISA included CVE-2026-63077 in its Known Exploited Vulnerabilities catalog. Federal agencies have been directed to apply the necessary patches within three days, as stipulated by Binding Operational Directive 26-04.
Currently, there is limited public information about the exploitation of this vulnerability. However, the inclusion in the KEV catalog highlights the critical nature of the flaw and the potential for significant impact if left unaddressed.
As cyber threats continue to evolve, organizations must remain vigilant and responsive to emerging vulnerabilities. Keeping software updated and applying timely patches are essential steps in maintaining robust cybersecurity defenses.
