---
schema: 1
kind: vulnerability
title: >
  CVE-2026-63077 — JetBrains TeamCity On-Premises: unauthenticated RCE through the agent-polling
  protocol, every on-prem version affected (CVSS 9.8)
headline: >
  JetBrains patches an unauthenticated remote-code-execution flaw reachable on every TeamCity
  On-Premises version ever shipped
summary: >
  JetBrains disclosed CVE-2026-63077 on 2026-07-27: an attacker with nothing more than HTTP(S)
  access to a TeamCity On-Premises server can exploit the agent-polling protocol to bypass
  authentication checks and execute arbitrary operating-system commands as the TeamCity server
  process. Every On-Premises version is affected; fixes are 2025.11.7 and 2026.1.3, with a
  security-patch plugin available down to 2017.1 for estates that cannot upgrade immediately.
  TeamCity Cloud is not affected and JetBrains reports no known exploitation. A build server
  compromise is a supply-chain compromise, and this product has been mass-exploited on an earlier
  flaw before.
discovered_at: "2026-07-29T05:05:00Z"
updated_at: "2026-08-06T04:11:48Z"
event_date: 2026-07-27
run_id: 2026-07-29T0408Z-intel
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - pre-auth
  - auth-bypass
  - supply-chain
  - patch-available
  - actively-exploited
  - cisa-kev
regions:
  - global
sectors:
  - public-sector
  - finance
  - telco
  - technology
entities: []
techniques:
  - T1190
  - T1059
affected_products:
  - JetBrains TeamCity On-Premises
cves:
  - id: CVE-2026-63077
    cvss: "9.8"
    epss: null
    type: deserialization
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
    affected: "All TeamCity On-Premises versions prior to the branch fixes; TeamCity Cloud is not affected."
    fixed: >
      2025.11.7 and 2026.1.3, with JetBrains' security-patch plugin as the mitigation path for
      installations from 2017.1 onward that cannot take the full upgrade.
sources:
  - url: "https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/"
    publisher: JetBrains (TeamCity PSIRT)
    date: 2026-07-27
    role: primary
  - url: "https://cveawg.mitre.org/api/cve/CVE-2026-63077"
    publisher: "MITRE CVE Record (CNA: JetBrains)"
    date: 2026-07-27
    role: corroborating
  - url: "https://www.cisa.gov/news-events/alerts/2026/08/05/cisa-adds-one-known-exploited-vulnerability-catalog"
    publisher: CISA
    date: 2026-08-05
    role: primary
closed_sources: []
evidence:
  - quote: "A critical security vulnerability has been identified in TeamCity On-Premises. If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process."
    publisher: JetBrains (TeamCity PSIRT)
  - quote: "This unauthenticated remote code execution vulnerability was reported to us privately on July 10, 2026, by Antoni Tremblay in accordance with our coordinated disclosure policy."
    publisher: JetBrains (TeamCity PSIRT)
  - quote: "At the time of publishing this advisory, we are not aware of any active exploitation of this vulnerability."
    publisher: JetBrains (TeamCity PSIRT)
  - quote: based on evidence of active exploitation
    publisher: CISA
  - quote: we are not aware of any active exploitation of this vulnerability
    publisher: JetBrains
verification: single-source
sourcing_note: >
  Effectively a single-authority disclosure. JetBrains' advisory is the sole primary, and the
  MITRE CVE record cited alongside it sits in JetBrains' own CNA container rather than being an
  independent assessment — the 9.8 score and the CWE-502 deserialization classification are
  JetBrains' self-assigned values, and neither figure appears in the prose advisory at all. Two
  details from that split are worth recording: JetBrains' own text never uses the word
  "deserialization", describing the impact only as bypassing authentication checks and executing
  operating-system commands, so the deserialization characterisation comes from the structured
  record; and CISA's ADP enrichment layer on the same record, dated 2026-07-28, independently
  assessed exploitation status as none, corroborating JetBrains' no-known- exploitation statement.
  The advisory deliberately withholds the specific gadget chain. A Cloud Security Alliance Lab
  Space note published 2026-07-28 was the discovery path for this item but is an automated
  re-reporting pipeline, so no fact here is carried from it — including its framing of an earlier
  mass-exploited TeamCity flaw and the state attribution attached to it, which neither cited
  source mentions and which is therefore stated here only as the general fact that the product has
  been mass-exploited before.
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Upgrade TeamCity On-Premises to 2025.11.7 or 2026.1.3 on the matching branch, or install JetBrains' security-patch plugin where the version is older than that but at least 2017.1 — and while the upgrade is scheduled, take the server's agent-polling endpoint off any internet-reachable interface, because the flaw needs nothing but HTTP(S) reachability."
  - "Treat any TeamCity On-Premises server that was internet-reachable and unpatched before 2026-08-05 as a compromise-assessment target rather than a completed patch: review build-agent registrations for agents you did not enrol, and rotate the VCS credentials, artifact-repository tokens and signing keys the server holds — an upgrade evicts the entry point but not what was taken through it."
updates:
  - at: "2026-08-06T04:11:48Z"
    run_id: 2026-08-06T0411Z-intel
    type: update
    summary: >
      CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog on 2026-08-05 based on
      evidence of active exploitation, changing the status of the unauthenticated JetBrains TeamCity
      On-Premises remote-code- execution flaw covered here on 2026-07-29 from patch-available to
      confirmed exploited. JetBrains' advisory, unchanged since 2026-07-27, still records that it was
      not aware of any active exploitation at publication. No authority has named an exploiting
      cluster or the observed intrusion path. Because every On-Premises version ever shipped is
      affected and the flaw needs only HTTP(S) reachability, any TeamCity server that was
      internet-reachable and unpatched before 2026-08-05 now warrants a compromise assessment rather
      than only an upgrade.
    fields:
      - actions
      - cves
      - evidence
      - sources
      - tags
      - body
    merged_from: 2026-08-06/cve-2026-63077-teamcity-kev-confirmed-exploited
migrated_from: null
---

JetBrains' advisory is short on mechanism by design and unambiguous on reach: an unauthenticated attacker with HTTP(S) access to a TeamCity On-Premises server can bypass authentication checks and run arbitrary operating-system commands with the privileges of the TeamCity server process, and every On-Premises version ever shipped is affected ([JetBrains, 2026-07-27](https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/)). The reachable surface is the agent-polling protocol — the channel distributed build agents use to check in with the central server for job assignments and configuration. JetBrains' own framing is that exploitation of the flaw requires no authentication and that the attacker bypasses authentication checks by way of that protocol, so there is no credential, session, or user interaction standing between a network-reachable server and command execution ([JetBrains, 2026-07-27](https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/)). The flaw was reported privately on 2026-07-10 by Antoni Tremblay, and JetBrains states it is not aware of any active exploitation as of publication ([JetBrains, 2026-07-27](https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/)); the CVE record filed by JetBrains as its own CNA carries the flaw as CWE-502, deserialization of untrusted data, at CVSS 9.8 ([MITRE CVE Record, 2026-07-27](https://cveawg.mitre.org/api/cve/CVE-2026-63077)).

The reason this warrants moving ahead of the ordinary patch queue is what a build server is, not the score. A TeamCity server holds the credentials its pipelines deploy with, the signing material its artifacts are stamped with, and write access to the outputs every downstream consumer trusts — so command execution as the server process converts into a durable ability to alter what future builds produce. Public exploitation of the present flaw has not been observed, and the honest reading of that is a clock rather than an all-clear — JetBrains withheld the gadget chain, but "all versions affected" plus "no authentication" plus a widely deployed, easily fingerprinted product is a combination that historically closes quickly once someone reconstructs the path.

Detection: the observable is in the web-server or reverse-proxy access log in front of TeamCity and in process-creation telemetry on the server host. Requests to the agent-polling endpoint arriving from addresses that are not your registered build agents are the first signal, and the second — the one that matters if the first was missed — is any child process spawned by the TeamCity server process that is not part of a build it was asked to run: shells, interpreters, or network utilities parented to the server rather than to an agent's build step. **Triage:** the agent-polling endpoint legitimately receives continuous check-in traffic from your build fleet, so request volume to it discriminates nothing on its own. Two things do. The source address set is finite and knowable — your registered agents are an inventory, so polling traffic from anything outside it is the anomaly. And on the server host, legitimate command execution belongs to agent processes running build steps; the server process itself spawning an interpreter or a network utility is not a quieter version of normal activity but a different thing entirely. Hardening: apply 2025.11.7 or 2026.1.3, or the security-patch plugin on 2017.1 and later, and treat the agent-polling interface as an internal service — if the only reason it faces the internet is that some agents live outside the network, a VPN or reverse tunnel for those agents removes the exposure that makes this flaw reachable at all.

## Update — 2026-08-06T04:11:48Z

CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog on 2026-08-05, stating it did so based on evidence of active exploitation ([CISA, 2026-08-05](https://www.cisa.gov/news-events/alerts/2026/08/05/cisa-adds-one-known-exploited-vulnerability-catalog)). That is the delta: the original entry recorded the flaw as patched but with no confirmed exploitation, which was also JetBrains' own position — its advisory states it was not aware of any active exploitation of the vulnerability at the time of publishing, and that advisory has not been revised since 2026-07-27 ([JetBrains, 2026-07-27](https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/)). Neither CISA's alert nor its catalog entry names an exploiting cluster, a victim set, or the observed intrusion path, so the confirmed fact is exploitation itself and nothing beyond it.

Nothing about the underlying flaw has changed. JetBrains describes it as letting an unauthenticated attacker with HTTP(S) access to a TeamCity server bypass authentication checks and execute arbitrary operating-system commands with the privileges of the TeamCity server process, affecting every On-Premises version ever shipped and leaving TeamCity Cloud unaffected ([JetBrains, 2026-07-27](https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/)). CISA's catalog entry names the flaw a deserialization of untrusted data vulnerability ([CISA, 2026-08-05](https://www.cisa.gov/news-events/alerts/2026/08/05/cisa-adds-one-known-exploited-vulnerability-catalog)); the vendor's own advisory describes the impact without using that term. What changes is the response owed by anyone who was slow to patch. A build server sits upstream of source code, artifact signing and deployment credentials, so the consequence of a week of exposure is not bounded by the server itself. The federal remediation deadline attached to the KEV listing is a US compliance date and carries no operational meaning for this constituency; the exploitation confirmation is what does.

**Defender takeaway:** the patch and the compromise assessment are now separate pieces of work, and doing only the first leaves the second undone. Behaviourally, the post-exploitation signal on a build server is the server process spawning command interpreters outside build execution, new or unexpected build agents appearing in the server's own agent registry, and reads of stored credential material by the server process at times unconnected to a running build — all visible in process-lineage and application-audit telemetry without any need for a signature. Because exploitation requires only network reachability, the exposure question to settle first is which TeamCity instances were reachable from the internet, not which were on the latest branch.
