Executive Summary
In July 2026, JetBrains disclosed a critical vulnerability (CVE-2026-63077) in TeamCity On-Premises, affecting all versions prior to 2025.11.7 and 2026.1.3. This flaw allows unauthenticated attackers with HTTP(S) access to execute arbitrary operating system commands on the TeamCity server by exploiting insecure deserialization in the agent polling protocol. Successful exploitation could lead to unauthorized access, data exfiltration, and compromise of CI/CD pipelines. JetBrains released patches in versions 2025.11.7 and 2026.1.3, along with a security patch plugin for versions 2017.1 and later. Organizations are urged to update their servers or apply the security patch plugin immediately to mitigate this risk. (blog.jetbrains.com)
The inclusion of CVE-2026-63077 in CISA's Known Exploited Vulnerabilities Catalog underscores the urgency of addressing this issue. (cisa.gov)
Why This Matters Now
The active exploitation of CVE-2026-63077 poses a significant threat to organizations using TeamCity On-Premises. Immediate remediation is crucial to prevent unauthorized access and potential compromise of critical systems.
Attack Path Analysis
An unauthenticated attacker exploited a deserialization vulnerability in JetBrains TeamCity's agent polling protocol to execute arbitrary commands on the server. This allowed the attacker to escalate privileges, move laterally within the network, establish command and control channels, exfiltrate sensitive data, and potentially disrupt CI/CD pipelines.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited a deserialization vulnerability in TeamCity's agent polling protocol, allowing unauthenticated remote code execution.
Related CVEs
CVE-2026-63077
CVSS 9.8In JetBrains TeamCity before 2026.1.3, 2025.11.7, unauthenticated remote code execution was possible via the agent polling protocol.
Affected Products:
JetBrains TeamCity – < 2026.1.3, < 2025.11.7
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter: PowerShell
Abuse Elevation Control Mechanism: Bypass User Account Control
Valid Accounts
Remote Services: SMB/Windows Admin Shares
Archive Collected Data: Archive via Utility
Exfiltration Over C2 Channel
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
JetBrains TeamCity vulnerability creates critical supply chain risks for development environments, requiring immediate patching and zero trust segmentation controls.
Information Technology/IT
DevOps infrastructure exposure through TeamCity deserialization vulnerability enables lateral movement and data exfiltration requiring enhanced east-west traffic security.
Financial Services
CI/CD pipeline compromise threatens regulatory compliance under PCI standards, demanding egress security controls and anomaly detection for development workflows.
Government Administration
Federal agencies must prioritize TeamCity remediation per BOD 26-04 requirements, implementing multicloud visibility and encrypted traffic controls immediately.
Sources
- CISA Adds One Known Exploited Vulnerability to Cataloghttps://www.cisa.gov/news-events/alerts/2026/08/05/cisa-adds-one-known-exploited-vulnerability-catalogVerified
- NVD - CVE-2026-63077https://nvd.nist.gov/vuln/detail/CVE-2026-63077Verified
- JetBrains Security Bulletinhttps://www.jetbrains.com/privacy-security/issues-fixed/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While the initial exploitation may still occur, the attacker's subsequent actions would likely be constrained, reducing the potential for further compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing the risk of gaining elevated access.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally would likely be constrained, reducing the risk of compromising additional systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels would likely be constrained, reducing the risk of persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing the risk of data loss.
The attacker's ability to disrupt CI/CD pipelines and compromise build artifacts would likely be constrained, reducing the risk of operational impact.
Impact at a Glance
Affected Business Functions
- Continuous Integration/Continuous Deployment (CI/CD) Pipelines
- Software Development Lifecycle Management
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of source code repositories and build artifacts.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict unauthorized lateral movement within the network.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts targeting known vulnerabilities.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual activities promptly.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
- • Regularly update and patch systems to mitigate known vulnerabilities and reduce the attack surface.



