News Room
16
Share
Metabase and JetBrains TeamCity Zero-Days Under Active Exploitation; CISA Issues Urgent KEV Warnings
criticalZero-Day Exploits

Metabase and JetBrains TeamCity Zero-Days Under Active Exploitation; CISA Issues Urgent KEV Warnings

Unauthenticated attackers are exploiting a CVSS 10.0 flaw in Metabase and a critical deserialization bug in JetBrains TeamCity. CISA has added these and a Progress LoadMaster vulnerability to its KEV catalog.

11 August 2026Last updated 18 August 20265 min readMandiant
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
Unknown
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2026-63077, CVE-2026-8037
Source:
Mandiant
Read Time:
5 min

Executive Summary

In the last 48 hours, the cybersecurity landscape has seen a significant escalation in the exploitation of enterprise-grade software. Intelligence reports from The Hacker News and CISA confirm that a maximum-severity zero-day in Metabase and a critical remote code execution (RCE) flaw in JetBrains TeamCity are being actively leveraged by threat actors. These vulnerabilities allow for unauthenticated administrative access and full system compromise, posing a critical risk to organizations utilizing these platforms for business intelligence and CI/CD operations.

Threat Analysis

The current threat landscape is characterized by a rapid pivot toward targeting the 'plumbing' of modern enterprises—specifically data visualization tools and DevOps pipelines. The Metabase zero-day (CVSS 10.0) is particularly dangerous as it grants full administrative control without requiring any valid credentials. Simultaneously, the exploitation of JetBrains TeamCity (CVE-2026-63077) follows a trend of attackers targeting supply chain infrastructure to facilitate lateral movement into production environments. These attacks are not isolated; they represent a coordinated effort by sophisticated actors to gain initial access to high-value corporate networks.

Technical Details

Metabase Zero-Day: The vulnerability impacts on-premise versions of Metabase. It is an authentication bypass flaw that allows an attacker to access the setup-token, which can then be used to create a new administrative account. Once administrative access is gained, attackers can execute arbitrary commands on the underlying server or exfiltrate sensitive database credentials.

JetBrains TeamCity (CVE-2026-63077): This vulnerability, with a CVSS score of 9.8, involves the deserialization of untrusted data. Attackers can send specially crafted requests to the TeamCity server, leading to unauthenticated RCE. According to SecurityWeek, this flaw is being used to deploy web shells and persistence mechanisms.

Progress LoadMaster (CVE-2026-8037): Additionally, CISA has flagged a command injection vulnerability in Progress LoadMaster that allows unauthenticated remote attackers to execute commands via the management interface. This was added to the Known Exploited Vulnerabilities (KEV) catalog on August 7, 2026.

Attribution Assessment

While specific attribution remains fluid, the tactics, techniques, and procedures (TTPs) observed in the TeamCity and Metabase exploitations align with known patterns of Initial Access Brokers (IABs) and state-sponsored Advanced Persistent Threats (APTs). The focus on CI/CD tools is a hallmark of groups like APT29, though current telemetry suggests a broader range of opportunistic cybercriminal groups are also joining the exploitation phase to deploy ransomware or sell access on dark web forums.

Implications

The successful exploitation of these tools provides a 'skeleton key' to an organization's most sensitive assets. For Metabase, the implication is the total exposure of connected data warehouses. For TeamCity, the risk is a full-scale supply chain compromise, where attackers can inject malicious code into software builds, affecting downstream customers and partners. The speed at which these vulnerabilities moved from disclosure to active exploitation (less than 72 hours) underscores the diminishing window for traditional patching cycles.

Recommendations

Encrygma Intelligence recommends the following immediate actions:

  1. Immediate Patching: Update Metabase to the latest patched version immediately. For JetBrains TeamCity, ensure all instances are running the version released on August 6, 2026, or later.
  2. Network Isolation: Isolate management interfaces for LoadMaster and TeamCity from the public internet. Use VPNs or Zero Trust Network Access (ZTNA) for administrative access.
  3. Credential Audit: Following a patch, audit all administrative accounts in Metabase and TeamCity for unauthorized additions.
  4. Threat Hunting: Review logs for unusual POST requests to /api/setup/validate (Metabase) and unexpected Java process executions (TeamCity).
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo