
Metabase and JetBrains TeamCity Zero-Days Under Active Exploitation; CISA Issues Urgent KEV Warnings
Unauthenticated attackers are exploiting a CVSS 10.0 flaw in Metabase and a critical deserialization bug in JetBrains TeamCity. CISA has added these and a Progress LoadMaster vulnerability to its KEV catalog.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- Unknown
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2026-63077, CVE-2026-8037
- Source:
- Mandiant
- Read Time:
- 5 min
Executive Summary
In the last 48 hours, the cybersecurity landscape has seen a significant escalation in the exploitation of enterprise-grade software. Intelligence reports from The Hacker News and CISA confirm that a maximum-severity zero-day in Metabase and a critical remote code execution (RCE) flaw in JetBrains TeamCity are being actively leveraged by threat actors. These vulnerabilities allow for unauthenticated administrative access and full system compromise, posing a critical risk to organizations utilizing these platforms for business intelligence and CI/CD operations.
Threat Analysis
The current threat landscape is characterized by a rapid pivot toward targeting the 'plumbing' of modern enterprises—specifically data visualization tools and DevOps pipelines. The Metabase zero-day (CVSS 10.0) is particularly dangerous as it grants full administrative control without requiring any valid credentials. Simultaneously, the exploitation of JetBrains TeamCity (CVE-2026-63077) follows a trend of attackers targeting supply chain infrastructure to facilitate lateral movement into production environments. These attacks are not isolated; they represent a coordinated effort by sophisticated actors to gain initial access to high-value corporate networks.
Technical Details
Metabase Zero-Day: The vulnerability impacts on-premise versions of Metabase. It is an authentication bypass flaw that allows an attacker to access the setup-token, which can then be used to create a new administrative account. Once administrative access is gained, attackers can execute arbitrary commands on the underlying server or exfiltrate sensitive database credentials.
JetBrains TeamCity (CVE-2026-63077): This vulnerability, with a CVSS score of 9.8, involves the deserialization of untrusted data. Attackers can send specially crafted requests to the TeamCity server, leading to unauthenticated RCE. According to SecurityWeek, this flaw is being used to deploy web shells and persistence mechanisms.
Progress LoadMaster (CVE-2026-8037): Additionally, CISA has flagged a command injection vulnerability in Progress LoadMaster that allows unauthenticated remote attackers to execute commands via the management interface. This was added to the Known Exploited Vulnerabilities (KEV) catalog on August 7, 2026.
Attribution Assessment
While specific attribution remains fluid, the tactics, techniques, and procedures (TTPs) observed in the TeamCity and Metabase exploitations align with known patterns of Initial Access Brokers (IABs) and state-sponsored Advanced Persistent Threats (APTs). The focus on CI/CD tools is a hallmark of groups like APT29, though current telemetry suggests a broader range of opportunistic cybercriminal groups are also joining the exploitation phase to deploy ransomware or sell access on dark web forums.
Implications
The successful exploitation of these tools provides a 'skeleton key' to an organization's most sensitive assets. For Metabase, the implication is the total exposure of connected data warehouses. For TeamCity, the risk is a full-scale supply chain compromise, where attackers can inject malicious code into software builds, affecting downstream customers and partners. The speed at which these vulnerabilities moved from disclosure to active exploitation (less than 72 hours) underscores the diminishing window for traditional patching cycles.
Recommendations
Encrygma Intelligence recommends the following immediate actions:
- Immediate Patching: Update Metabase to the latest patched version immediately. For JetBrains TeamCity, ensure all instances are running the version released on August 6, 2026, or later.
- Network Isolation: Isolate management interfaces for LoadMaster and TeamCity from the public internet. Use VPNs or Zero Trust Network Access (ZTNA) for administrative access.
- Credential Audit: Following a patch, audit all administrative accounts in Metabase and TeamCity for unauthorized additions.
- Threat Hunting: Review logs for unusual POST requests to
/api/setup/validate(Metabase) and unexpected Java process executions (TeamCity).
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Zero-Day Exploitation Campaign Targets Citrix NetScaler ADC and Gateway Appliances Globally

Critical Zero-Day Exploitation Confirmed in Citrix NetScaler ADC and Gateway Appliances

