logo

U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog

ID: 8cafb668-b2b8-5129-bab9-d791f923bc4f

STIX ID: report--8cafb668-b2b8-5129-bab9-d791f923bc4f

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: Pierluigi Paganini

...
...

The U.S. CISA added JetBrains TeamCity vulnerability CVE-2026-63077 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog; the flaw allows unauthenticated attackers to bypass authentication and execute arbitrary OS commands on on-prem TeamCity servers. JetBrains released security updates (2025.11.7 / 2026.1.3), a patch plugin for older versions, and recommends restricting network access; CISA ordered federal agencies to remediate by August 8, 2026. No active exploitation was observed at disclosure time.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.