InfoSec News Nuggets – 08/06/2026
Brief
Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability
CISA added CVE-2026-63077, a critical unauthenticated remote code execution flaw in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog after confirming active exploitation, giving federal agencies just three days to patch under Binding Operational Directive 26-04. The deserialization vulnerability, rated CVSS 9.
8, lets an attacker with mere HTTP or HTTPS access to a TeamCity server bypass authentication entirely via the agent polling protocol and execute arbitrary OS commands with the privileges of the server process — no credentials or user interaction required.
