Back to Blog
CVE-2026-63077: JetBrains TeamCity — Unauthenticated RCE Under Exploit (August 2026)
vulnerabilities

CVE-2026-63077: JetBrains TeamCity — Unauthenticated RCE Under Exploit (August 2026)

breachwire TeamAug 7, 20262 min read

CVE-2026-63077 — JetBrains TeamCity

CVE-2026-63077 is a critical vulnerability enabling unauthenticated remote code execution (RCE) on JetBrains TeamCity on-premise servers. The flaw is under active exploitation, with CISA confirming attackers are bypassing authentication to execute arbitrary OS commands. This exposes build pipelines, stored credentials, and server configurations to compromise.

Attack Vector

Attackers exploit a flaw in the TeamCity agent polling protocol, sending crafted requests that bypass authentication controls. No valid credentials are required; a remote attacker can directly execute arbitrary commands on the underlying OS. This can result in exposure or manipulation of build artifacts, credential theft, and downstream CI/CD compromise. No specific IOCs are published, but abnormal agent polling traffic or unexpected command execution from unauthenticated sources should be investigated.

Who Is at Risk

All organizations running on-premise instances of JetBrains TeamCity are at immediate risk. Cloud-hosted TeamCity SaaS is not affected. Enterprises with exposed TeamCity servers, especially those accessible from the internet, face heightened threat. CISA has confirmed exploitation in the wild, and all regions are impacted.

Patch & Mitigate

  • Patch: Apply the official JetBrains security update for CVE-2026-63077 immediately. Check JetBrains advisories for the exact fixed version and patch deadline.
  • Workaround: If patching is delayed, restrict network access to TeamCity servers and disable unnecessary agent connections.
  • Detect: Review logs for unauthenticated agent polling attempts, unexpected OS command execution, and anomalous changes to build artifacts or server configurations.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers exploit exposed TeamCity servers to gain a foothold without authentication.
  • TA0005 — Defense Evasion: Malicious commands are executed in the context of legitimate build processes, masking attacker activity.

Source: https://thehackernews.com/2026/08/cisa-flags-teamcity-cve-2026-63077-rce.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: