Government Advisory

Actively Exploited JetBrains TeamCity Vulnerability Added to CISA's Must-Patch List

CISA · 5 Aug 2026
Key Takeaway If your business uses JetBrains TeamCity, check your version immediately and apply the latest security patch to close this actively exploited vulnerability.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability, CVE-2026-63077, to its Known Exploited Vulnerabilities (KEV) Catalog. The flaw affects JetBrains TeamCity, a popular software development and CI/CD platform, and relates to how the software handles untrusted data during deserialization—a common and dangerous class of bug that attackers frequently use to gain control of systems.

CISA confirmed there is evidence this vulnerability is already being actively exploited in the wild. While the agency's Binding Operational Directive 26-04 legally requires US federal agencies to patch such vulnerabilities on a priority basis, CISA strongly encourages all organisations, including small and medium businesses, to review their exposure and remediate promptly.

For Australian businesses using JetBrains TeamCity for software development pipelines, this is a timely reminder that development tools are just as attractive to attackers as traditional business systems—especially when they are internet-facing. Unpatched development infrastructure can give attackers a foothold to access source code, credentials, and downstream customer systems.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.