U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog
ID: 8cafb668-b2b8-5129-bab9-d791f923bc4f
STIX ID: report--8cafb668-b2b8-5129-bab9-d791f923bc4f
Feed Name: Security Affairs
The U.S. CISA added JetBrains TeamCity vulnerability CVE-2026-63077 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog; the flaw allows unauthenticated attackers to bypass authentication and execute arbitrary OS commands on on-prem TeamCity servers. JetBrains released security updates (2025.11.7 / 2026.1.3), a patch plugin for older versions, and recommends restricting network access; CISA ordered federal agencies to remediate by August 8, 2026. No active exploitation was observed at disclosure time.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
