A critical vulnerability in JetBrains TeamCity, tracked as CVE-2026-63077, has been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog, indicating that it is being actively exploited by attackers. The flaw, which has a CVSS score of 9.8, allows unauthenticated attackers to execute arbitrary commands on affected systems. JetBrains released security updates for TeamCity On-Premises at the end of July to address this issue. The addition of CVE-2026-63077 to CISA's catalog1 suggests that the vulnerability is a high priority for patching. This vulnerability poses a significant risk to organizations using TeamCity, as exploitation could lead to complete system compromise. The active discussion involving CISA regarding the exploitation status of this vulnerability underscores the need for prompt action. So what matters to practitioners is that they should prioritize patching this vulnerability immediately to prevent potential attacks.