Hackers are already exploiting a serious flaw in TeamCity, a program many companies use to build their applications. The United States cybersecurity agency has confirmed it and has given until August 8 to fix it.
Imagine a factory where a brand’s cars are assembled. If someone gets into that factory at night and tampers with the assembly line, all the cars that come out the next day carry the hidden defect. Something similar has happened with TeamCity: a program that serves as a "software factory" for thousands of companies. A security flaw allows an attacker to get in without a password, and the US cybersecurity agency (CISA) has confirmed that real attacks are already underway.
What TeamCity is and why it matters
TeamCity is a program created by the company JetBrains. Many companies around the world use it to build their applications: the programmer writes the code (the instructions) and TeamCity takes care of "assembling" the application, checking that it works and leaving it ready for customers. It is like an automatic assembly line for software.
That is why a flaw in TeamCity does not affect just one company: if the attacker gets into the "factory", they can touch the final product that is later distributed to thousands or millions of users.
What happened
The flaw, catalogued as CVE-2026-63077, was discovered in early July. A researcher notified JetBrains, which published the fix at the end of that month: versions 2025.11.7 and 2026.1.3 are already patched. The problem has maximum severity (9.8 out of 10) and allows entering the server without a password or user account.
The real problem is that not everyone has updated. And last August 5, the United States cybersecurity agency (CISA) added this flaw to its list of vulnerabilities already being exploited in real attacks. That list is the maximum alarm signal: it means there are hackers using it right now. CISA has given US federal agencies until August 8 to fix it.
It is not the first time
TeamCity has been a target before. Ransomware groups and government-sponsored hackers have exploited previous flaws (such as CVE-2023-42793 or CVE-2024-27198) to break into companies that had not updated. The lesson repeats itself: if the server stays unpatched, the attackers end up finding it.
Why it is so dangerous
The worst part is that the attacker needs no password or user account. It is enough for the TeamCity server to be connected to the internet to try to get in. Once inside, the hacker can do almost anything: steal stored passwords, change the configuration or hide malicious code inside the applications the company is going to send to its customers.
That last point is the most feared: it is called a supply-chain attack. Instead of attacking each user one by one, the hacker poisons the product at its origin, like someone contaminating food before it reaches the supermarket. That way, the damage multiplies effortlessly.
Does it affect me?
Probably not directly: TeamCity is not a program ordinary people install at home. It is used by software companies, game studios and public bodies. But it does affect you as a user: many of the applications you use daily (banks, stores, games) may have been built with tools like this. If one of those companies suffers an attack, its app could reach your phone with an unpleasant surprise.
The good news is that there is nothing to do at home. The responsibility lies with the companies.
What companies should do
The solution is simple to explain but urgent: update. JetBrains has already published the patched versions (2025.11.7 and 2026.1.3) and also a special patch for old versions. Companies that use TeamCity in the cloud (TeamCity Cloud) do not have to do anything, because the manufacturer has already protected it.
Updating is like getting vaccinated: you do it once and it closes the door to the problem. Whoever does not do it is left with the door open.
The lesson of this story is that software is also manufactured on assembly lines, and that the security of those workshops matters as much as that of any factory. If your company or your job uses TeamCity, now is the time to check the version. The clock is already ticking.






