securityonline.info 8/24/2026, 7:51:23 AM · external

CVE-2026-63077 lets attackers hijack JetBrains TeamCity servers

CVE-2026-63077 lets attackers hijack JetBrains TeamCity servers
Developing story incident 18 articles tracked
JetBrains TeamCity unauthenticated remote code execution flaw (CVE-2026-63077)
CyberSIXT Evidence Panel
Primary Source blog.jetbrains.com
CISA KEV Listed in KEV
Patch Patch Available

THE page discusses a critical vulnerability (CVE-2026-63077) in JetBrains TeamCity that allows unauthenticated remote code execution. Attackers are actively exploiting this flaw, confirmed by Australia's ACSC. The CVE has a CVSS score of 9.8, marking it as critical. Affected versions are those prior to 2026.1.3 and 2025.11.7. Rapid7 provides a detailed analysis and proof-of-concept. The vulnerability could compromise CI/CD pipelines, potentially exposing sensitive information and altering deployment processes. Users are advised to patch their systems immediately and review their security settings to mitigate risks.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline