VMTech
Discuss a project

CISA lists actively exploited TeamCity remote code execution flaw

CISA lists actively exploited TeamCity remote code execution flaw

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-63077, a critical vulnerability in on-premise JetBrains TeamCity, to its Known Exploited Vulnerabilities catalog after identifying active exploitation. The flaw has a CVSS score of 9.8 and can enable unauthenticated remote code execution through TeamCity’s agent polling protocol.

JetBrains has released updates for affected on-premise installations. CISA said federal civilian executive branch agencies must prioritize remediation, with patches or mitigations due by August 8, 2026 under Binding Operational Directive 26-04.

Authentication bypass through agent polling

CVE-2026-63077 is a deserialization of untrusted data vulnerability. An attacker with access to a TeamCity server could exploit the agent polling protocol, bypass authentication checks, and execute arbitrary operating-system commands.

The commands would run with the privileges assigned to the TeamCity server process. As a result, the practical impact depends on how that process is configured and what access it holds in the environment.

JetBrains said a successful compromise may expose TeamCity data, configuration information, and stored credentials. It may also allow changes to server state and create a route to compromise build artifacts and downstream CI/CD pipelines.

Active exploitation raises the priority

CISA’s KEV entry indicates that the vulnerability is being exploited in the wild. The available information does not identify the threat actors involved, the exploitation method, or the scale of the activity. JetBrains had not updated its advisory to confirm active exploitation at the time of the report.

The case illustrates how weaknesses in build and delivery infrastructure can become broader operational security concerns. In borrowed trust as a cyber-security tactic, borrowed trust is examined as a central cyber-security tactic, a context that is relevant when systems responsible for software builds, credentials, and deployment inputs are exposed.

What organisations should do

Teams operating TeamCity on premises should apply JetBrains updates as soon as possible. They should also establish which accounts and resources the TeamCity server process can access, because those privileges determine the scope available after code execution.

A practical business implication is to treat this patch as a CI/CD security priority: inventory on-premise TeamCity servers, update them, and assess exposure of credentials, build artifacts, and connected delivery systems.

#cybersecurity#teamcity#cicd#vulnerability
Open analytics
On the site 0 views
min read 3 06.08.2026
Instagram

CISA lists actively exploited TeamCity remote code execution flaw

Open the post on Instagram ↗