2026-08-06 · view entry permalink →
CVE-2026-63077 — TeamCity On-Premises moves to confirmed exploitation on the CISA KEV catalog, nine days after JetBrains said it had seen none
UPDATE · originally covered CVE-2026-63077 — JetBrains TeamCity On-Premises: unauthenticated RCE through the agent-polling protocol, every on-prem version affected (CVSS 9.8) (2026-07-29)
CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog on 2026-08-05, stating it did so based on evidence of active exploitation (CISA, 2026-08-05). That is the delta: the original entry recorded the flaw as patched but with no confirmed exploitation, which was also JetBrains' own position — its advisory states it was not aware of any active exploitation of the vulnerability at the time of publishing, and that advisory has not been revised since 2026-07-27 (JetBrains, 2026-07-27). Neither CISA's alert nor its catalog entry names an exploiting cluster, a victim set, or the observed intrusion path, so the confirmed fact is exploitation itself and nothing beyond it.
Nothing about the underlying flaw has changed. JetBrains describes it as letting an unauthenticated attacker with HTTP(S) access to a TeamCity server bypass authentication checks and execute arbitrary operating-system commands with the privileges of the TeamCity server process, affecting every On-Premises version ever shipped and leaving TeamCity Cloud unaffected (JetBrains, 2026-07-27). CISA's catalog entry names the flaw a deserialization of untrusted data vulnerability (CISA, 2026-08-05); the vendor's own advisory describes the impact without using that term. What changes is the response owed by anyone who was slow to patch. A build server sits upstream of source code, artifact signing and deployment credentials, so the consequence of a week of exposure is not bounded by the server itself. The federal remediation deadline attached to the KEV listing is a US compliance date and carries no operational meaning for this constituency; the exploitation confirmation is what does.