PatchSiren cyber security CVE debrief
CVE-2024-27199 JetBrains CVE debrief
CVE-2024-27199 is a JetBrains TeamCity relative path traversal vulnerability that CISA has added to the Known Exploited Vulnerabilities catalog. Because CISA also records known ransomware campaign use, organizations running TeamCity should treat remediation as urgent and follow vendor and CISA guidance without delay.
- Vendor
- JetBrains
- Product
- TeamCity
- CVSS
- HIGH 7.3
- CISA KEV
- Listed
- Original CVE published
- 2026-04-20
- Original CVE updated
- 2026-04-20
- Advisory published
- 2026-04-20
- Advisory updated
- 2026-04-20
Who should care
Organizations running JetBrains TeamCity, especially security, DevOps, and IT teams responsible for patching, hardening, and monitoring CI/CD infrastructure.
Technical summary
The supplied source data identifies CVE-2024-27199 as a relative path traversal issue in JetBrains TeamCity. CISA’s KEV listing indicates known exploitation, and the record also marks known ransomware campaign use, so defenders should prioritize mitigation and removal of exposure over routine patch scheduling.
Defensive priority
Immediate
Recommended defensive actions
- Review JetBrains TeamCity vendor guidance and apply the recommended mitigations or fixes as soon as possible.
- Follow CISA BOD 22-01 guidance where applicable, especially for cloud services.
- If mitigations are unavailable, discontinue use of the affected product or isolate the deployment until it is remediated.
- Confirm exposure and remediation status across all TeamCity instances before the CISA due date.
Evidence notes
This debrief is limited to the supplied CISA KEV metadata and the official reference URLs listed in that record (JetBrains issues-fixed page, JetBrains blog update, NVD, and CVE.org). The corpus provided here does not include the full advisory text, so version-specific details are intentionally omitted.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-27199 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-27199
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-27199 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-27199
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.