← nejvýznamnější zprávy · všechny zprávy

SPOJENO PŘES CVE KEV ✓ EPSS 0.87

JetBrains Cadence Compromised via Exploitation of TeamCity Vulnerability (Incident)

Cadence uses JetBrains TeamCity to orchestrate cloud workloads, and the affected server, api.cadence.jetbrains.com, remained vulnerable to CVE-2026-63077 despite having been intended for patching. Threat actors exploited the vulnerability beginning on August 8 to gain unauthor...

Číst originál na Wiz Research →

5 zpráv z 4 zdrojů · první 29. 7. 18:16 · poslední 1. 9. 02:00 CZ · EN/orig

JetBrains veřejná správa US

tg: incident tg: zneužíváno tg: zranitelnost tg: rozbor

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-63077 9.8 3.1 · JetBrains KEV ✓ 0.87

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.

Jak se o tom psalo 5

  1. · Wiz Research US nadpis události

    JetBrains Cadence Compromised via Exploitation of TeamCity Vulnerability (Incident)

    Cadence uses JetBrains TeamCity to orchestrate cloud workloads, and the affected server, api.cadence.jetbrains.com, remained vulnerable to CVE-2026-63077 despite having been intended for patching. Threat actors exploited the vulnerability beginning on August 8 to gain unauthor...

  2. · Rapid7 US

    Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)

    OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unsafe deserialization vulnerability affecting JetBrains TeamCity. An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling protocol without credentials and execute operating system commands with the privileges of the TeamCity server process.JetBrains reported no known active exploitation when it disclosed the vulnerability. However, on August 5, 2026, CISA added…

  3. · CISA Advisories US

    CISA Adds One Known Exploited Vulnerability to Catalog

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for…

  4. · CISA KEV US

    JetBrains TeamCity Deserialization of Untrusted Data Vulnerability (CVE-2026-63077)

    CISA added CVE-2026-63077 to the Known Exploited Vulnerabilities catalog. Affected product: JetBrains TeamCity. Remediation due date: 2026-08-08.

  5. · Rapid7 US

    CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

    OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8. An unauthenticated remote attacker with HTTP(S) access to a TeamCity server can exploit the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity…