Interestana
Home/News/CISA Warns of Active Exploitation for TeamCity RCE Vulnerability
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

CISA Warns of Active Exploitation for TeamCity RCE Vulnerability

CISA Warns of Active Exploitation for TeamCity RCE Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical remote code execution (RCE) vulnerability in on-premise versions of JetBrains TeamCity that is currently being actively exploited in the wild. This vulnerability, designated as CVE-2026-63077, carries a high severity score of 9.8 on the Common Vulnerability Scoring System (CVSS). The flaw stems from the deserialization of untrusted data, which could enable an unauthenticated attacker with access to a TeamCity server to execute arbitrary code. This means an attacker could potentially gain complete control over the affected TeamCity instance without needing any credentials.

JetBrains, the developer of TeamCity, released a patch for this vulnerability on March 13, 2026. The advisory from CISA urges all users of TeamCity to apply the available security updates immediately to mitigate the risk of exploitation. TeamCity is a widely used continuous integration and continuous delivery (CI/CD) server, often employed by software development teams to automate the building, testing, and deployment of applications. Its critical role in the software development lifecycle makes vulnerabilities within it particularly concerning, as a compromise could lead to the disruption of development pipelines, the theft of sensitive source code, or the injection of malicious code into software releases.

The active exploitation in the wild signifies that malicious actors have already discovered and are leveraging this flaw to compromise systems. This elevates the urgency for organizations to patch their TeamCity installations, as attackers may already be targeting vulnerable servers. CISA's inclusion of CVE-2026-63077 on its Known Exploited Vulnerabilities (KEV) catalog mandates federal agencies to apply the patch by April 3, 2026, to prevent further compromises. While this mandate applies to federal agencies, CISA strongly encourages all organizations using TeamCity to prioritize this update regardless of their sector.

The vulnerability's nature, allowing unauthenticated remote code execution, presents a significant threat. An attacker could potentially use this access to move laterally within an organization's network, access other internal systems, or deploy further malicious payloads. The CI/CD pipeline is a prime target for attackers seeking to disrupt operations or inject malware into software supply chains, as demonstrated by numerous past incidents. Therefore, securing TeamCity instances is paramount for maintaining the integrity and security of software development processes and the resulting products. Organizations are advised to consult JetBrains' official security advisories for detailed information on the affected versions and the patching process.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next