Critical JetBrains TeamCity Flaw Now Under Active Attack
Security researchers have confirmed that attackers are actively exploiting a newly disclosed vulnerability in JetBrains TeamCity, a popular continuous integration and deployment (CI/CD) platform used by software development teams. The flaw, tracked as CVE-2026-63077, is rated critical because it allows remote code execution without requiring any authentication, meaning attackers could potentially take control of affected systems without needing a username or password.
TeamCity is widely used by organisations to automate software builds, testing, and deployment pipelines. Because these systems often have access to source code, credentials, and deployment infrastructure, a successful compromise could give attackers a foothold to steal sensitive data, inject malicious code into software products, or move further into a company's network.
While TeamCity is more commonly used by larger development teams, small and medium businesses that rely on outsourced developers, managed IT providers, or software vendors using this platform should be aware that a breach upstream could affect them indirectly. Businesses running TeamCity should check for available patches from JetBrains and apply them urgently, as exploitation is already underway.