ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)

criticalVulnerability exploited in the wildimportance 60CVE-2026-63077

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-63077
Unauthenticated Deserialization RCE in JetBrains TeamCity On-Premises

CVE-2026-63077 is a critical (CVSS 9.8) unauthenticated remote code execution vulnerability in JetBrains TeamCity, caused by deserialization of untrusted data (CWE-502) in the agent polling protocol. An attacker with network access to the TeamCity server, but no credentials of any kind, can send maliciously crafted serialized input to the agent polling endpoint and execute arbitrary code on the server. Successful exploitation yields full server takeover, exposing source code, build logs, stored secrets and credentials, and providing a pivot point into build agents and connected infrastructure; related headlines describe a real breach in which AWS credentials were extracted from an unpatched TeamCity instance. Organizations running TeamCity On-Premises in versions prior to the fixes (2025.11.7 or 2026.1.3, depending on branch) are affected, while the JetBrains-hosted cloud service is not indicated as impacted. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-08-05, EPSS is 86.5% (100th percentile), and no public PoC is known, meaning defenders cannot rely on public scanners alone and should assume sophisticated attackers are targeting exposed servers.

Do: Upgrade immediately to TeamCity 2025.11.7 or 2026.1.3, whichever branch you run; because the flaw is pre-authentication, also hunt for signs of compromise (unexpected builds or agents, new or modified admin users, altered build configurations, and leaked stored credentials/secrets) per vendor guidance, and restrict internet exposure of the TeamCity server until patched. Federal agencies must apply vendor mitigations or discontinue use per CISA BOD 26-04 and the KEV required action, including the Forensics Triage Requirements.

9.887% KEV
  • JetBrains TeamCity On-Premises all versions before 2025.11.7 (2025.11 branch) and before 2026.1.3 (2026.1 branch)
largetens of thousands of internet-exposed TeamCity on-premises servers (order of magnitude 10k-100k); total on-premises installs likely higher
Full article446 words · extracted from helpnetsecurity.com · click to collapse

JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible.

“For those who are unable to do so, we have released a security patch plugin,” noted Daniel Gallo, Solutions Engineering Lead at JetBrains.

TeamCity as a possible target

JetBrains TeamCity is a widely used continuous integration and continuous delivery (CI/CD) server solution.

It’s available as a JetBrains-hosted option (TeamCity Cloud) or can be self-hosted and administered by customers (TeamCity On-Premises), either on their own hardware or in a private or public cloud.

State-sponsored hacking groups and ransomware affiliates have been known to leverage vulnerabilities in unpatched TeamCity On-Premises servers in the past.

About CVE-2026-63077

Discovered and privately disclosed earlier this monht by security researcher Antoni Tremblay, CVE-2026-63077 is exploitable via the TeamCity agent polling protocol and may allow attackers to bypass authentication checks and execute OS commands with the privileges of the TeamCity server process.

“Depending on the privileges granted to the TeamCity server process, a successful attack could expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines,” Gallo explained.

JetBrains has already implemented the fix for TeamCity Cloud deployments, and is now advising customers to do the same on their self-hosted instances, as CVE-2026-63077 affects all TeamCity On-Premises versions.

The company said it checked TeamCity Cloud environments for signs of exploitation attempts and found none.

“At the time of publishing this advisory, we are not aware of any active exploitation of this vulnerability,” they added.

What to do?

TeamCity On-Premises customers should upgrade to version 2025.11.7 or 2026.1.3, or implement the security patch plugin if they still run v2017.1+.

Those running TeamCity v2017.1 to v2018.1 must restart the server after installing the patch, but starting from TeamCity v2018.2 admins can enable the plugin without that step.

To mitigate the risk of exploitation through this and similar vulnerabilities, JetBrains advises limiting network access to TeamCity servers to trusted networks (if possible), or limiting access to internet-facing TeamCity servers by requiring VPN connections or implementing an additional security layer.

“Even exposing the TeamCity login screen or REST API can provide attackers with potential entry points to exploit newly disclosed vulnerabilities,” the company noted.

“We also recommend running the TeamCity server with the minimum operating system privileges required for normal operation.”

UPDATE (August 6, 2026, 02:55 a.m. ET):

CISA has added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog and ordered US civilian federal agencies to remediate it by August 8, 2026.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/07/28/teamcity-rce-cve-2026-63077-fixed/