Threat actors are exploiting CVE-2026-63077, a critical JetBrains TeamCity vulnerability that can allow unauthenticated remote code execution through HTTP/S requests. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and is urging rapid patching of TeamCity On-Premises systems. #JetBrains #TeamCity #CVE202663077 #CISA
Keypoints
- CISA says attackers are exploiting a recently patched TeamCity flaw.
- CVE-2026-63077 is a critical deserialization vulnerability with a 9.8 CVSS score.
- The bug can let unauthenticated attackers execute remote code via HTTP/S requests.
- All TeamCity On-Premises versions are affected.
- JetBrains and CISA urge organizations to apply the available patches immediately.
Read More: https://www.securityweek.com/hackers-start-exploiting-recent-jetbrains-teamcity-vulnerability/