ctipilot.ch
← Back to the live brief
HIGHCVE-2026-63077exploitedupdateNATOA2vulnerability

CVE-2026-63077 — TeamCity On-Premises moves to confirmed exploitation on the CISA KEV catalog, nine days after JetBrains said it had seen none

discovered 2026-08-06 04:11 UTCrun 2026-08-06T0411Z-intel2 sourcessingle-source · national CERT

UPDATE · originally covered CVE-2026-63077 — JetBrains TeamCity On-Premises: unauthenticated RCE through the agent-polling protocol, every on-prem version affected (CVSS 9.8) (2026-07-29)

CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog on 2026-08-05, stating it did so based on evidence of active exploitation (CISA, 2026-08-05). That is the delta: the original entry recorded the flaw as patched but with no confirmed exploitation, which was also JetBrains' own position — its advisory states it was not aware of any active exploitation of the vulnerability at the time of publishing, and that advisory has not been revised since 2026-07-27 (JetBrains, 2026-07-27). Neither CISA's alert nor its catalog entry names an exploiting cluster, a victim set, or the observed intrusion path, so the confirmed fact is exploitation itself and nothing beyond it.

Nothing about the underlying flaw has changed. JetBrains describes it as letting an unauthenticated attacker with HTTP(S) access to a TeamCity server bypass authentication checks and execute arbitrary operating-system commands with the privileges of the TeamCity server process, affecting every On-Premises version ever shipped and leaving TeamCity Cloud unaffected (JetBrains, 2026-07-27). CISA's catalog entry names the flaw a deserialization of untrusted data vulnerability (CISA, 2026-08-05); the vendor's own advisory describes the impact without using that term. What changes is the response owed by anyone who was slow to patch. A build server sits upstream of source code, artifact signing and deployment credentials, so the consequence of a week of exposure is not bounded by the server itself. The federal remediation deadline attached to the KEV listing is a US compliance date and carries no operational meaning for this constituency; the exploitation confirmation is what does.

based on evidence of active exploitation

CISA 2026-08-05

we are not aware of any active exploitation of this vulnerability

JetBrains 2026-07-27

Defender actions

  • Treat any TeamCity On-Premises server that was internet-reachable and unpatched before 2026-08-05 as a compromise-assessment target rather than a completed patch: review build-agent registrations for agents you did not enrol, and rotate the VCS credentials, artifact-repository tokens and signing keys the server holds — an upgrade evicts the entry point but not what was taken through it.

ATT&CK mapping

2 techniques mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

Execution TA0002
T1059Command and Scripting Interpreter

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.