Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-63077

Published 2026-07-27
Updated 2 months ago
Vendor/s
JetBrains
Product/s
TeamCity
Version/s
* > 2025.11.7
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

Critical unauthenticated RCE (CVSS 9.8) in JetBrains TeamCity via agent polling protocol. Actively exploited; immediate patching is required.

CPE

JetBrains logo
JetBrains
Product Version Start Version End (excl.) Status
teamcity * 2025.11.7 vulnerable
teamcity 2026.1 2026.1.3 vulnerable

Related weakness (CWE)

CWE-502

Remediation plan

1

Apply official patches

Immediately update your JetBrains TeamCity server to version 2026.1.3, 2025.11.7, or the latest available security release to resolve the RCE vulnerability in the agent polling protocol.

2

Update affected systems

Identify all TeamCity instances within your environment and ensure they are no longer running versions earlier than 2025.11.7 or versions in the 2026.1 branch prior to 2026.1.3.

3

Restrict access

Use firewalls or security groups to restrict access to the TeamCity server's agent communication ports, ensuring only known, authorized build agent IP addresses can reach the polling protocol.

4

Monitor for exploitation

Review TeamCity server logs and system process trees for unauthorized command execution or suspicious Java deserialization artifacts, specifically focusing on the agent-to-server communication channel.

Detection Guidance

"Monitor network traffic for unusual payloads targeting the TeamCity agent polling endpoints. Specifically, look for indicators of Java deserialization (CWE-502) within the agent-server handshake. Use EDR tools to detect suspicious child processes, such as shell executions (cmd.exe, /bin/sh), spawned by the TeamCity service. Additionally, audit the TeamCity 'Authorized Agents' list for any unrecognized agents that may have been registered by an attacker to facilitate code execution."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management