CVE-2023-42793Active Exploitation(jetbrains / teamcity)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for jetbrains teamcity systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

7.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-10-25. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-288CWE-306

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • teamcity

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-09-06)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
teamcity

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-27: 1Mentions · 2026-07-12: 1Mentions · 2026-09-06: 2PoC Mentioned / Linked · 2026-07-12: 1PoC Mentioned / Linked · 2026-09-06: 1Exploit Tool / Code · 2026-09-06: 1Active Exploitation · 2026-02-27: 1Technical Details · 2026-07-12: 1Technical Details · 2026-09-06: 102-2707-1209-06
Signal classification4 categories
Active Exploitation
125.0%
PoC
125.0%
Disclosure
125.0%
Exploit
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-271
Active Exploitation1
2026-07-121
PoC1
2026-09-062
Disclosure1Exploit1
Full discourse4 posts
  • SOCRadar®@socradar
    Active Exploitation

    North Korean state-backed group Andariel is actively exploiting critical vulnerabilities like CVE-2023-46604 and CVE-2023-42793. Leveraging tools like Ladon and AnyDesk, they are backdooring networks. Read more at the link below. https://socradar.io/blog/dark-web-profile-andariel/ #CyberSecurity #Andariel #ThreatIntel

    Post summary

    North Korean-backed Andariel is reported to actively exploit CVE-2023-46604 and CVE-2023-42793 using tools such as Ladon and AnyDesk, indicating ongoing in‑the‑wild attacks.

    0601610804
    5.6K followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-86zVCPW [CRITICAL/PoC] Linked: CVE-2023-42793 CVE-2023-42793-TeamCity-Unauthenticated-RCE 🔗 https://exploitgrid.net/exploits/57c56f80-6b5b-46f8-952b-f9d794320fe9

    Post summary

    The snippet announces a publicly available PoC and exploit for CVE-2023-42793, an unauthenticated remote‑code‑execution flaw in TeamCity, with a direct exploit link.

    1000049
    40 followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2026-27941 CVE-2026-31852 CVE-2026-56290 CVE-2026-7873 CVE-2023-42793 ..🧵👇

    Post summary

    The tweet is a daily digest announcing the disclosure of five critical CVEs.

    1000049
    40 followersView on X
  • r0otk3r@r0otk3r
    PoC

    🚨 CVE-2023-42793: Critical 9.8 CVSS JetBrains TeamCity Unauthenticated RCE https://www.youtube.com/watch?v=PZQh3aWcfbo #Cybersecurity #Infosec #AppSec #RCE #JetBrains #TeamCity #CICD #AuthBypass #CVE202342793 #PoC #EthicalHacking #BugBounty #PatchNow https://t.co/FjpeUCN85S

    Post summary

    The tweet announces a critical JetBrains TeamCity RCE CVE, shares a YouTube video that serves as a proof‑of‑concept, but does not provide a patch, active exploitation evidence, or code.

    0001059
    43 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjetbrainsteamcity---

Explore more