Executive Summary
In July 2026, JetBrains identified a critical security vulnerability (CVE-2026-63077) in all versions of TeamCity On-Premises. This flaw allows unauthenticated attackers with HTTP(S) access to bypass authentication and execute arbitrary operating system commands with the privileges of the TeamCity server process. The vulnerability stems from insecure deserialization in the agent polling protocol, enabling remote code execution without credentials or user interaction. JetBrains released patches in versions 2025.11.7 and 2026.1.3 to address this issue. (blog.jetbrains.com)
The incident underscores the importance of promptly applying security updates to prevent potential exploitation. Organizations using TeamCity On-Premises should upgrade to the patched versions or apply the provided security patch plugin to mitigate the risk of unauthorized access and potential compromise of build environments. (blog.jetbrains.com)
Why This Matters Now
This vulnerability poses a significant risk to organizations relying on TeamCity for their CI/CD pipelines, as it allows unauthenticated remote code execution, potentially leading to data breaches and system compromises. Immediate action is required to apply the necessary patches and secure affected systems. (blog.jetbrains.com)
Attack Path Analysis
An unauthenticated attacker exploited a critical vulnerability in TeamCity's agent polling protocol to execute arbitrary OS commands, leading to full system compromise. The attacker escalated privileges by executing commands with the same rights as the TeamCity server process. They then moved laterally within the network, accessing connected systems and CI/CD pipelines. Establishing command and control, the attacker maintained persistent access to the compromised environment. Sensitive data, including source code and stored credentials, was exfiltrated. The attack culminated in the potential modification of server states and build artifacts, compromising the integrity of the CI/CD pipeline.
Kill Chain Progression
Initial Compromise
Description
An unauthenticated attacker exploited a critical vulnerability in TeamCity's agent polling protocol to execute arbitrary OS commands, leading to full system compromise.
Related CVEs
CVE-2026-63077
CVSS 9.8A critical vulnerability in JetBrains TeamCity On-Premises allows unauthenticated remote attackers to execute arbitrary code on the server.
Affected Products:
JetBrains TeamCity On-Premises – All versions prior to 2025.11.7 and 2026.1.3
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Client Execution
Process Injection
Valid Accounts
File and Directory Discovery
Data from Local System
Exfiltration Over C2 Channel
Inhibit System Recovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 2.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Critical TeamCity vulnerability (CVE-2026-63077) enables unauthenticated remote code execution, threatening CI/CD pipelines and requiring immediate patches for secure development operations.
Information Technology/IT
TeamCity flaw allows attackers OS-level access without authentication, compromising IT infrastructure management and demanding urgent security updates across enterprise environments.
Financial Services
Software vulnerability in TeamCity poses severe compliance risks for financial institutions, potentially exposing sensitive data through compromised build systems and development workflows.
Health Care / Life Sciences
Critical TeamCity security flaw threatens HIPAA compliance through potential unauthorized access to healthcare development environments and patient data processing systems.
Sources
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging Inhttps://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.htmlVerified
- JetBrains TeamCity Official Websitehttps://www.jetbrains.com/teamcity/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit the vulnerability may have been limited by enforcing strict identity-based access controls and segmenting workloads to reduce unauthorized access.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been constrained by implementing strict segmentation policies that limit access based on identity and role.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement may have been limited by enforcing east-west traffic controls that restrict unauthorized inter-workload communication.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels could have been constrained by continuous monitoring and control of network traffic across multicloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts may have been limited by enforcing strict egress policies that control outbound data flows.
The attacker's ability to modify server states and build artifacts could have been constrained by enforcing strict segmentation and identity-aware policies, reducing the scope of impact.
Impact at a Glance
Affected Business Functions
- Continuous Integration/Continuous Deployment (CI/CD) Pipelines
- Software Build and Deployment Processes
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of source code repositories and build artifacts.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict unauthorized access and limit lateral movement within the network.
- • Deploy East-West Traffic Security controls to monitor and control internal traffic, preventing unauthorized communications between systems.
- • Utilize Multicloud Visibility & Control solutions to gain comprehensive insights into network activities and detect anomalies.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
- • Apply Inline IPS (Suricata) to detect and prevent exploitation attempts by inspecting network traffic for known attack patterns.



