INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

U.S. CISA Adds JetBrains TeamCity Flaw to Known Exploited Vulnerabilities

| 2026-08-06 08:22 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a JetBrains TeamCity vulnerability, tracked as CVE-2026-63077, to its Known Exploited Vulnerabilities catalog. This critical security flaw allows an unauthenticated attacker with access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands, potentially compromising sensitive data, credentials, configurations, and CI/CD pipelines. The vulnerability has been identified in the software version 2025.11.7 or later, but a security patch plugin is available for organizations unable to immediately upgrade. Users are advised to upgrade to versions 2026.1.3 or later by August 8th of this year.
Technical Mitigations AI-generated
* Restrict network access to TeamCity servers and apply least-privilege configurations to prevent unauthorized access. * Run TeamCity on dedicated hosts separated from build agents to reduce the attack surface. * Install security patch plugin for organizations unable to immediately upgrade TeamCity to versions 2025.11.7 or 2026.1.3, which fixes only CVE-2026-63077 and can be installed on TeamCity 2017.1 and later. * Implement VPN access or add extra security controls on internet-facing TeamCity servers to protect against potential entry points for attackers exploiting newly disclosed vulnerabilities. * Regularly review the Known Exploited Vulnerabilities (KEV) catalog and address vulnerabilities in infrastructure, as recommended by CISA orders federal agencies to fix the vulnerability by the end of this week.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-63077CVE-2026-63077
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎2026.1.3
Threat actors exploited a JetBrains TeamCity vulnerability in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog, prompting CISA to release a security patch plugin for organizations unable to immediately upgrade TeamCity to 2026.1.3.
infrastructure 2025.11.7
infrastructure 2026.1.3
‎Aug 06, 2026
U.S. CISA added a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog on August 6, 2026.
‎2026/08/06
The threat actors used a JetBrains TeamCity flaw to target the U.S. Cybersecurity and Infrastructure Security Agency (CISA) by exploiting CVE-2026-63077, a deserialization of untrusted data vulnerability that allowed them to execute arbitrary OS commands with TeamCity server privileges.
organisation JetBrains
organisation TeamCity On-Premises
organisation CVE-2026-63077
organisation the Common
infrastructure 2025.11.7
infrastructure 2026.1.3
organisation TeamCity
organisation CI
‎August 8, 2026
U.S. CISA adds JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog, ordering federal agencies by August 8, 2026, to fix the vulnerability or apply software patches.
attribution CVE-2026-63077
Tactical Metrics
Metrics
infrastructure
‎2025.11.7
Software Version
Metrics
infrastructure
‎2026.1.3
Software Version