Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert confirming that threat actors have begun actively exploiting a recent vulnerability in JetBrains TeamCity. This critical flaw, identified as CVE-2026-63077 with a CVSS score of 9.8, allows unauthenticated attackers to achieve remote code execution by bypassing authentication through the agent polling protocol.
The issue affects all TeamCity On-Premises versions and stems from the improper deserialization of untrusted data over HTTP/S. While JetBrains released fixes in versions 2025.11.7 and 2026.1.3 (along with a security plugin for older builds) prior to reporting this active exploitation, CISA has now listed the vulnerability in its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply patches within three days.