Your Software Factory Just Got Hacked. What the TeamCity Zero-Day Means for Every Business.
CISA confirmed active exploitation of CVE-2026-63077 in JetBrains TeamCity today. If your developers build software — or if any vendor does on your behalf — your CI/CD pipeline is now an active attack surface.
This morning, CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog and set a federal patch deadline of August 8, 2026 — 48 hours from now. The vulnerability is in JetBrains TeamCity, a widely used CI/CD platform. And it's being actively exploited in the wild.
If you've never heard of TeamCity, you're not alone. But here's why it matters: TeamCity is the system many development teams use to automatically build, test, and deploy software. It sits at the center of what's called the CI/CD pipeline — the automated factory that turns code into running applications.
And an attacker with access to that factory doesn't just steal data. They can poison the source.
What the Vulnerability Does
CVE-2026-63077 carries a CVSS score of 9.8 out of 10 — as critical as it gets. The flaw is in TeamCity On-Premises (self-hosted versions), and it affects all versions of the software. Every single one.
Here's what an attacker can do with it: using nothing more than network access to a TeamCity server, with no username, no password, and no prior credentials whatsoever, they can bypass authentication entirely and execute arbitrary commands on the server with the privileges of the TeamCity process itself.
That last part matters. TeamCity typically runs with elevated permissions because it needs them — it's pulling code, running tests, packaging builds, and pushing software to production environments. An attacker who controls TeamCity controls that entire pipeline.
JetBrains patched the flaw on July 27, 2026. CISA confirmed active exploitation today, August 6. That's ten days between patch and confirmed attacks — which means the attackers moved fast.
What They Can Do Once They're In
This isn't just a server compromise. It's a supply chain breach opportunity.
Once inside TeamCity, an attacker can:
Steal stored credentials and secrets. TeamCity holds API keys, cloud credentials, database passwords, and deployment tokens needed to push software to production. These are the keys to your kingdom.
Tamper with build artifacts. An attacker can modify what gets compiled and packaged — inserting backdoors into software before it ships. Your customers or internal users then receive compromised software you unknowingly signed and distributed.
Access source code repositories. TeamCity is connected to your code. Everything your developers have built is potentially exposed.
Compromise downstream CI/CD pipelines. If your TeamCity instance feeds into other systems — cloud environments, container registries, deployment pipelines — those become reachable from the same compromise.
This is exactly the attack pattern used in the SolarWinds breach, one of the most damaging supply chain attacks in history. Attackers got into the build system and poisoned the software before it shipped.
The History Lesson Business Leaders Should Know
TeamCity has been targeted before. In 2024, Russian state-sponsored actors (specifically SVR/Cozy Bear, the same group behind SolarWinds) exploited a different TeamCity vulnerability to compromise software development environments across government agencies and private companies. CISA and the FBI issued a joint advisory.
This is not a coincidence. CI/CD platforms are premium targets because they sit upstream of everything else. Attack the factory, and you control the product.
Who Is at Risk?
Any organization running TeamCity On-Premises that hasn't patched to version 2025.11.7 or 2026.1.3 is vulnerable. TeamCity Cloud instances were already patched by JetBrains — that's not where the risk lives.
But the risk extends further than organizations that run TeamCity themselves. If you use custom software built by a development shop, an MSP, or an internal team — and that team uses TeamCity — you're downstream of their pipeline. If they get hit, what they build for you could be compromised.
The Verizon 2026 Data Breach Investigations Report found a 60% surge in third-party vendor involvement in breaches. CI/CD platform attacks are exactly how that happens at scale.
Three Questions Every Business Leader Should Be Asking Right Now
1. Do you or any of your software vendors run JetBrains TeamCity On-Premises?
This is the first thing to find out. Ask your IT team. Ask your software vendors. Ask your MSP. If the answer is yes, find out immediately which version they're running and whether they've applied the patch. The federal deadline is August 8. Don't wait.
2. What credentials does your CI/CD pipeline hold, and where does it have access?
CI/CD systems are necessarily privileged. They need keys to push code to production. That means a compromise isn't isolated — it's a pivot point into cloud environments, production databases, and customer-facing systems. You need to know what's stored there and what it can reach.
3. Can you detect tampering in your build pipeline?
This is the hard question. Most organizations monitor their networks and endpoints. Far fewer monitor the integrity of their software build process. If an attacker modifies what gets built and deployed, how would you know? Artifact signing, build provenance tracking, and pipeline integrity monitoring are not optional anymore — they're table stakes for organizations that build or consume custom software.
What to Do in the Next 48 Hours
If you run TeamCity On-Premises: patch immediately to 2025.11.7 or 2026.1.3. JetBrains also released a patch plugin for organizations running versions back to 2017.1 that can't immediately upgrade. There is no workaround — only the patch fixes this.
Rotate credentials. Even if you're not sure you were compromised, rotate every API key, cloud token, and deployment secret that TeamCity had access to. If an attacker got in before your patch, those credentials are burned.
Check your logs. Look for unusual commands executed by the TeamCity service account, unexpected network connections from the TeamCity server, or any changes to build configurations or artifact outputs you didn't authorize.
Ask your software vendors the same questions. Your patch won't help if your development vendor is still exposed.
The Bigger Picture
CVE-2026-63077 is one more data point in a pattern that should be getting business leaders' attention: attackers are moving up the supply chain. They're not just targeting your endpoints or your inboxes anymore. They're targeting the systems that build and deliver the software your organization runs.
When the factory is compromised, everything downstream is suspect.
If you're not sure where your organization stands on CI/CD security, software supply chain risk, or patch velocity — TrustPoint Cyber can help you find out. Start with a conversation. We'll tell you what you actually need to know.
Ready to strengthen your security?
TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.