THREAT actors are exploiting a recently patched vulnerability in JetBrains TeamCity, a critical CI/CD platform. The vulnerability, tracked as CVE-2026-63077 with a CVSS score of 9.8, is related to deserialization of untrusted data, allowing unauthenticated attackers to achieve remote code execution via HTTP/S requests. This issue affects all TeamCity On-Premises versions, enabling attackers to bypass authentication checks and execute arbitrary commands with the TeamCity server's privileges.
JetBrains has urged organizations to apply patches included in versions 2025.11.7 and 2026.1.3. The U.S. cybersecurity agency CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, advising federal agencies to patch it within three days. Currently, no active exploitation has been reported.