The Australian Cyber Security Centre says attackers are actively exploiting CVE-2026-63077 in JetBrains TeamCity On-Premises, a critical flaw that lets an unauthenticated user with HTTP(S) access run operating system commands. JetBrains later said it had also seen attempted exploitation against unpatched servers.
TeamCity is a CI/CD controller, so the bug sits in the software delivery path, not just on one host. If the service is exposed, skipping the login check can hand an attacker control over the machine that builds, tests, and deploys code, which turns a server patch into a workflow risk.
JetBrains says fixes are in TeamCity 2025.11.7 and 2026.1.3, or in the security patch plugin, and the repeated TeamCity exploitation history makes exposed instances a recurring target rather than a one-off. Any internet-reachable TeamCity server now sits in the active attack path until it is updated.