CISA Warns of TeamCity RCE Vulnerability Actively Exploited in Attacks
ID: fcc1a33b-9113-56ef-bfa7-56e6116256b0
STIX ID: report--fcc1a33b-9113-56ef-bfa7-56e6116256b0
Feed Name: cybersecurityNews.com
CISA has warned that CVE-2026-63077, an unauthenticated deserialization RCE in JetBrains TeamCity On‑Premises, is being actively exploited; JetBrains published fixes (2025.11.7 and 2026.1.3) and CISA added the issue to its Known Exploited Vulnerabilities catalog with a remediation deadline. The report highlights severe supply‑chain risk from compromised build servers, recommends urgent patching or applying the vendor security plugin as a temporary measure, restricting access, reviewing logs and builds for signs of compromise, rotating secrets, and preserving forensic evidence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
