Actively Exploited JetBrains TeamCity Vulnerability Added to CISA's Must-Patch List
The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability, CVE-2026-63077, to its Known Exploited Vulnerabilities (KEV) Catalog. The flaw affects JetBrains TeamCity, a popular software development and CI/CD platform, and relates to how the software handles untrusted data during deserialization—a common and dangerous class of bug that attackers frequently use to gain control of systems.
CISA confirmed there is evidence this vulnerability is already being actively exploited in the wild. While the agency's Binding Operational Directive 26-04 legally requires US federal agencies to patch such vulnerabilities on a priority basis, CISA strongly encourages all organisations, including small and medium businesses, to review their exposure and remediate promptly.
For Australian businesses using JetBrains TeamCity for software development pipelines, this is a timely reminder that development tools are just as attractive to attackers as traditional business systems—especially when they are internet-facing. Unpatched development infrastructure can give attackers a foothold to access source code, credentials, and downstream customer systems.