06/08/2026
π¨ CISA Alert Critical TeamCity RCE Vulnerability Actively Exploited
CVE-2026-63077has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog, confirming active exploitation in the wild.
Attackers can exploit this vulnerability to:
π΄ Execute remote code
π΄ Gain unauthorized access
π΄ Compromise TeamCity build servers
π΄ Disrupt CI/CD pipelines and the software supply chain
π‘οΈ Recommended Actions
β
Update TeamCity to the latest patched version
β
Restrict external access to TeamCity servers
β
Monitor logs for suspicious activity
β
Review credentials and security configurations
Stay Alert. Patch Quickly. Protect Your Infrastructure.