THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical JetBrains TeamCity vulnerability (CVE-2026-63077) to its Known Exploited Vulnerabilities catalog. This vulnerability, with a CVSS score of 9.8, allows unauthenticated attackers to execute arbitrary commands on affected servers. JetBrains has released security updates for impacted on-premises versions, while cloud instances have been patched.
Organizations are advised to upgrade to versions 2025.11.7 or 2026.1.3 or use a security patch plugin available for older versions. CISA mandates federal agencies to resolve this vulnerability by August 8, 2026.