Security Affairs
U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog|Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records|AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems|Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals|U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog|OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root|SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access|SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency|INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit|CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access|U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog|31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register|U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog|Snowflake Hacker Pleads Guilty After Breaching 165 Companies and Stealing Billions of Records|AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems|Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals|U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog|OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root|SMOKE#SCREEN Campaign Abuses ScreenConnect to Give Attackers Remote Control Access|SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency|INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit|CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access|U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog|31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a JetBrains TeamCity vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a JetBrains TeamCity vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. At the end of July, JetBrains released security updates for TeamCity […]

CISA Minnesota Attacks

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a JetBrains TeamCity vulnerability to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a JetBrains TeamCity vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog.

At the end of July, JetBrains released security updates for TeamCity On-Premises after discovering the critical vulnerability CVE-2026-63077. The flaw could allow unauthenticated attackers to execute arbitrary commands on affected servers. All on-premise versions are impacted, while TeamCity Cloud instances have already been patched. Users are advised to upgrade to versions 2025.11.7 or 2026.1.3.

“A critical security vulnerability has been identified in TeamCity On-Premises and assigned the Common Vulnerabilities and Exposures (CVE) identifier CVE-2026-63077.” reads the advisory. “If exploited, this vulnerability may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands.”

The TeamCity vulnerability affects servers exposed via HTTP(S) and can be exploited without authentication through the agent polling protocol. An attacker could bypass authentication and execute arbitrary OS commands with TeamCity server privileges, potentially accessing sensitive data, credentials, configurations, altering server settings, and compromising CI/CD pipelines. JetBrains recommends restricting network access, applying least-privilege configurations, and running TeamCity on dedicated hosts separated from build agents. No active exploitation has been observed at disclosure time.

The company has also released a security patch plugin for organizations unable to immediately upgrade TeamCity to versions 2025.11.7 or 2026.1.3. The plugin fixes only CVE-2026-63077 and can be installed on TeamCity 2017.1 and later. For newer versions, security patches can be managed directly from the administration console.

“The security patch plugin will address only the vulnerability described above (CVE-2026-63077).” continues the advisory.”We always recommend upgrading your server to the latest version to benefit from many other security updates.”

JetBrains recommends protecting internet-facing TeamCity servers by requiring VPN access or adding extra security controls. Exposing login pages or REST APIs can provide attackers with potential entry points to exploit newly disclosed vulnerabilities.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerability by the end of this week, on August 8, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)