CVE-2026-63077
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: in JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent…
CISA federal remediation date Aug 8 · date passed
Vulnerabilities · 10h ago
CISA warned federal agencies on Wednesday that ransomware gangs are actively exploiting a critical JetBrains TeamCity flaw, CVE-2026-63077, after JetBrains had already shipped a fix in July. The bug affects TeamCity, the CI/CD server many teams use to coordinate builds and agents.
The flaw is an unauthenticated remote code execution issue in TeamCity’s agent polling protocol: a remote caller can send attacker-controlled requests to the endpoint and make the server run code without logging in. In practice, that turns the build orchestrator into initial access, not just a place to run builds, so compromise can reach source access, signing keys, and other credentials the server holds.
For organizations that let TeamCity sit near their software supply chain, the exposure outlives the server patch itself: once the CI layer is owned, the attacker is already inside the software factory. Government and other high-value environments running TeamCity inherit that blast radius until the build trust chain is treated as part of incident scope.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: in JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent…
CISA federal remediation date Aug 8 · date passed
1 source covering this story
CISA: Ransomware gangs now exploiting critical TeamCity flaw
Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July.
Part of the PlainSec briefing for 2026-09-24