A newly patched security flaw affecting on-premise versions of JetBrains TeamCity has been actively exploited in the wild, as reported by the U.S This article explores attacker access teamcity. . Cybersecurity and Infrastructure Security Agency (CISA).

The vulnerability at issue is a deserialization of untrusted data that could enable an unauthenticated attacker with access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. "Cybersecurity experts have identified a deserialization flaw in JetBrains' TeamCity, which allows an unauthenticated remote code execution via the agent polling protocol," CISA stated.

"This vulnerability can be exploited by an attacker who gains access to the TeamCity environment through the agent polling protocol." When TeamCity is running with certain permissions, an attacker could gain access to sensitive information like configuration details and authentication tokens. This unauthorized exposure can lead to a breach in data security, alter system settings, and jeopardize the reliability of builds generated by the build server.

As stated by JetBrains, this poses significant risks to both the internal operations and external dependencies of CI/CD pipelines. The exploit method remains undisclosed, along with the identities of the attackers behind these incidents and their scope. JetBrains hasn't confirmed any ongoing exploits in its advisories.

Given the current update, on-premise users should expedite their patch application as soon as possible. According to Binding Operational Directive (BOD) 26-04, federal civilian executive branch agencies must prioritize addressing high-risk vulnerabilities from the Known Exploited Vulnerabilities (KEV) catalog by August 8, 2026.