INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
U.S. CISA Adds JetBrains TeamCity Flaw to Known Exploited Vulnerabilities
| 2026-08-06 08:22 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a JetBrains TeamCity vulnerability, tracked as CVE-2026-63077, to its Known Exploited Vulnerabilities catalog. This critical security flaw allows an unauthenticated attacker with access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands, potentially compromising sensitive data, credentials, configurations, and CI/CD pipelines. The vulnerability has been identified in the software version 2025.11.7 or later, but a security patch plugin is available for organizations unable to immediately upgrade. Users are advised to upgrade to versions 2026.1.3 or later by August 8th of this year.
Technical Mitigations AI-generated
* Restrict network access to TeamCity servers and apply least-privilege configurations to prevent unauthorized access.
* Run TeamCity on dedicated hosts separated from build agents to reduce the attack surface.
* Install security patch plugin for organizations unable to immediately upgrade TeamCity to versions 2025.11.7 or 2026.1.3, which fixes only CVE-2026-63077 and can be installed on TeamCity 2017.1 and later.
* Implement VPN access or add extra security controls on internet-facing TeamCity servers to protect against potential entry points for attackers exploiting newly disclosed vulnerabilities.
* Regularly review the Known Exploited Vulnerabilities (KEV) catalog and address vulnerabilities in infrastructure, as recommended by CISA orders federal agencies to fix the vulnerability by the end of this week.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-63077CVE-2026-63077
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
2026.1.3
Threat actors exploited a JetBrains TeamCity vulnerability in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog, prompting CISA to release a security patch plugin for organizations unable to immediately upgrade TeamCity to 2026.1.3.
Click on any entity below to view its context and source!
infrastructure
2025.11.7
The company has also released a security patch plugin for organizations unable to immediately upgrade TeamCity to versions 2025.11.7 or 2026.1.3.
infrastructure
2026.1.3
The company has also released a security patch plugin for organizations unable to immediately upgrade TeamCity to versions 2025.11.7 or 2026.1.3.
Aug 06, 2026
U.S. CISA added a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog on August 6, 2026.
2026/08/06
The threat actors used a JetBrains TeamCity flaw to target the U.S. Cybersecurity and Infrastructure Security Agency (CISA) by exploiting CVE-2026-63077, a deserialization of untrusted data vulnerability that allowed them to execute arbitrary OS commands with TeamCity server privileges.
Click on any entity below to view its context and source!
organisation
JetBrains
At the end of July, JetBrains
released
security updates for TeamCity On-Premises after discovering the critical vulnerability CVE-2026-63077.
According to JetBrains, the vulnerability can be exploited by an unauthenticated attacker via the TeamCity agent polling protocol to sidestep authentication checks and execute arbitrary operating system commands.
organisation
TeamCity On-Premises
At the end of July, JetBrains
released
security updates for TeamCity On-Premises after discovering the critical vulnerability CVE-2026-63077.
organisation
CVE-2026-63077
“A critical security vulnerability has been identified in TeamCity On-Premises and assigned the Common Vulnerabilities and Exposures (CVE) identifier CVE-2026-63077.” reads the
advisory
.
organisation
the Common
“A critical security vulnerability has been identified in TeamCity On-Premises and assigned the Common Vulnerabilities and Exposures (CVE) identifier CVE-2026-63077.” reads the
advisory
.
infrastructure
2025.11.7
Users are advised to upgrade to versions
2025.11.7 or 2026.1.3
.
infrastructure
2026.1.3
Users are advised to upgrade to versions
2025.11.7 or 2026.1.3
.
organisation
TeamCity
An attacker could bypass authentication and execute arbitrary OS commands with TeamCity server privileges, potentially accessing sensitive data, credentials, configurations, altering server settings, and compromising CI/CD pipelines.
A successful attack can expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines, per JetBrains.
organisation
CI
An attacker could bypass authentication and execute arbitrary OS commands with TeamCity server privileges, potentially accessing sensitive data, credentials, configurations, altering server settings, and compromising CI/CD pipelines.
A successful attack can expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines, per JetBrains.
August 8, 2026
U.S. CISA adds JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog, ordering federal agencies by August 8, 2026, to fix the vulnerability or apply software patches.
Click on any entity below to view its context and source!
attribution
CVE-2026-63077
The deadline by which federal agencies must apply software patches or mitigations for CVE-2026-63077 is August 8, 2026.
Tactical Metrics
Metrics
infrastructure
2025.11.7
Software Version
Click for context!
Users are advised to upgrade to versions
2025.11.7 or 2026.1.3
.
The company has also released a security patch plugin for organizations unable to immediately upgrade TeamCity to versions 2025.11.7 or 2026.1.3.
Metrics
infrastructure
2026.1.3
Software Version
Users are advised to upgrade to versions
2025.11.7 or 2026.1.3
.
The company has also released a security patch plugin for organizations unable to immediately upgrade TeamCity to versions 2025.11.7 or 2026.1.3.
Intelligence Sources
Security Affairs
2026-08-06
The Hacker News
2026-08-06
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-06T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
6x
organisation
Identified Entity
JetBrains
entity
5x
timeline
Temporal Reference
August 8, 2026
date
2x
infrastructure
Software Version
2025.11.7
version
Contextual Telemetry
Context Block
9 METRICS
vulnerability
Exploited CVE
CVE-2026-63077
cve
vulnerability
CVSS Score
10
score
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
general metric
Critical Vulnerability
63,077
critical vulnerability
general metric
Teamcity
2,017
teamcity
general metric
Score
10
score
tactic
Cyber Operation Type
Remote Code Execution
tactic
general metric
Aug
6
aug
general metric
Binding Operational Directive
26
binding operational directive
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.