TL;DR
CISA added the TeamCity vulnerability CVE-2026-63077 to its Known Exploited Vulnerabilities catalog. The flaw allows unauthenticated remote code execution on TeamCity On-Premises servers. Federal agencies must patch by August 8, 2026.
- CVE: CVE-2026-63077
- CVSS: 9.8 (Critical · CVSSv3)
- Product: JetBrains TeamCity
- Affected: < 2026.1.3, 2025.11.7
- Impact: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was...
- Status: Exploited in the wild
- Patched in: 2026.1.3, 2025.11.7
- EPSS: 0.6% (30-day)
- Action: Update to 2026.1.3, 2025.11.7 now
Why This TeamCity Vulnerability Matters
TeamCity runs build pipelines for thousands of software teams. Therefore, a server compromise can poison downstream code. A successful attack can expose stored credentials, alter server state, and taint build artifacts.
CISA acted on evidence of active exploitation. As a result, it placed the bug in the KEV catalog and set a firm remediation deadline.
How the Attack Works
The flaw stems from deserialization of untrusted data. An unauthenticated attacker only needs HTTP(S) access to the server.
According to the JetBrains advisory, the attacker abuses the TeamCity agent polling protocol. This bypasses authentication checks. It then runs operating system commands with the privileges of the server process.
Affected Versions
All versions of TeamCity On-Premises are affected. TeamCity Cloud customers need no action, since JetBrains already applied fixes. The vendor also confirms no evidence of Cloud environments being exploited.
Patch and Mitigation Steps
Update your server without delay. JetBrains fixed the flaw in versions 2025.11.7 and 2026.1.3.
Cannot upgrade yet? A security patch plugin covers TeamCity 2017.1 and later. Beyond patching, restrict server access to trusted networks. Additionally, run TeamCity with minimum privileges and on hosts separate from build agents.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.