# Critical JetBrains TeamCity Flaw Actively Exploited by Hackers

*Published August 7, 2026*
*Source: [https://www.securityweek.com/hackers-start-exploiting-recent-jetbrains-teamcity-vulnerability/](https://www.securityweek.com/hackers-start-exploiting-recent-jetbrains-teamcity-vulnerability/)*

## Executive Summary

A critical vulnerability in JetBrains TeamCity, CVE-2026-63077, is being actively exploited, allowing attackers to execute remote code without authentication. CISA has urged immediate patching to protect systems against this severe threat.

## Article

Recently, a significant security flaw in JetBrains TeamCity has come under active exploitation, according to a warning from the US Cybersecurity and Infrastructure Security Agency (CISA). TeamCity, a key platform for continuous integration and delivery in software development, has a vulnerability tracked as CVE-2026-63077. This vulnerability, with a critical CVSS score of 9.8, allows unauthenticated attackers to execute remote code via HTTP/S requests.

The flaw affects all on-premises versions of TeamCity, enabling attackers to bypass authentication and execute commands with the server's privileges. JetBrains has released patches to address this issue in versions 2025.11.7 and 2026.1.3, along with a security patch plugin for version 2017.1 and later. Despite these updates, JetBrains emphasizes the urgency for organizations to apply these patches swiftly to safeguard their systems.

JetBrains noted that this security defect was reported privately and initially, there were no known active exploitations. However, in response to growing concerns, CISA has added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch it within three days. This swift action underscores the severity of potential threats posed by this vulnerability.

While specific details on the exploitation remain limited, organizations using TeamCity are strongly advised to prioritize these updates to mitigate the risk of unauthorized system access and potential damage.
