CISA Warned of Critical TeamCity Security Flaw

Federal officials alerted organizations to a critical remote code execution vulnerability in JetBrains TeamCity.

Updated on Sept. 24, 2026 in Cybersecurity

Isometric editorial illustration of server racks and networking cables, representing secure software infrastructure.
The Cybersecurity and Infrastructure Security Agency has issued a warning regarding a critical remote code execution vulnerability found in JetBrains TeamCity build server software. AI Illustration. Upload story photo >

Live Poll

Do you feel confident that the software used by your employer is adequately protected from cyberattacks?

The Cybersecurity and Infrastructure Security Agency has issued an urgent warning regarding a critical remote code execution flaw in JetBrains TeamCity software. The vulnerability allows unauthorized actors to gain control of build servers without requiring credentials.

Why it matters

Attackers exploit these build servers to inject malicious code into legitimate software builds and gain access to high-value signing keys. By compromising this central hub in the CI/CD pipeline, adversaries can pivot into downstream production infrastructure.

The vulnerability is tracked as CWE-502 and involves an unauthenticated remote code execution via the agent polling protocol. This flaw allows an attacker with network access to the server to exploit the system without providing any credentials.

The players

Cybersecurity and Infrastructure Security Agency

This federal agency is responsible for protecting the nation's critical infrastructure and provides guidance on cybersecurity threats.

JetBrains

This international software development company provides the TeamCity build server software targeted by this vulnerability.

The details

Attackers target build servers because they function as critical chokepoints, providing access to cloud credentials and sensitive signing keys. Once access is obtained through the agent polling protocol, malicious actors can compromise the software delivery chain.

Timeline

  1. September 23, 2026: CISA issued the official security warning.

The Tech Race

This incident highlights the ongoing shift toward targeting software supply chains rather than traditional perimeter defenses. By compromising build servers, attackers bypass standard security checks that have replaced legacy software development methods.

Organizations using affected build servers must immediately investigate their infrastructure for signs of unauthorized access or compromised signing keys. Failure to patch these systems could expose sensitive intellectual property and allow attackers to plant malicious code in downstream products.

The takeaway

Security teams should prioritize updating their build environments to prevent lateral movement within their production networks. Securing the CI/CD pipeline is now a fundamental requirement for maintaining the integrity of modern software development operations.

Further reading

Learn more about securing software infrastructure in our Cybersecurity section.

Source note: This article includes information reported by SC Media.

Live Poll

Do you feel confident that the software used by your employer is adequately protected from cyberattacks?