Threat Intelligence

US Cybersecurity Agency Warns of Active Attacks on JetBrains TeamCity Servers

The Hacker News · 6 Aug 2026
Key Takeaway If your business runs an on-premise TeamCity server, patch it immediately and check for signs of compromise, as attackers are already exploiting this flaw.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that a critical vulnerability in on-premise installations of JetBrains TeamCity is being actively exploited by attackers. The flaw, tracked as CVE-2026-63077, carries a severe CVSS score of 9.8 and stems from the way the software processes untrusted data during deserialization.

What makes this vulnerability particularly dangerous is that it does not require the attacker to have valid login credentials. Anyone with network access to a vulnerable TeamCity server could potentially exploit the flaw to run malicious code, giving attackers a foothold to compromise development pipelines, steal source code, or move deeper into a business's network.

TeamCity is widely used by software development teams to automate the building, testing, and deployment of applications, making it an attractive target for attackers seeking access to sensitive intellectual property or supply chain footholds. Businesses using on-premise TeamCity deployments should treat this as an urgent priority, as CISA's alert confirms exploitation is already occurring rather than being a theoretical risk.

TeamCity CISA RCE vulnerability software supply chain patch management
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.