Critical unauthenticated RCE (CVSS 9.8) in JetBrains TeamCity via agent polling protocol. Actively exploited; immediate patching is required.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| teamcity | * | 2025.11.7 | vulnerable |
| teamcity | 2026.1 | 2026.1.3 | vulnerable |
Immediately update your JetBrains TeamCity server to version 2026.1.3, 2025.11.7, or the latest available security release to resolve the RCE vulnerability in the agent polling protocol.
Identify all TeamCity instances within your environment and ensure they are no longer running versions earlier than 2025.11.7 or versions in the 2026.1 branch prior to 2026.1.3.
Use firewalls or security groups to restrict access to the TeamCity server's agent communication ports, ensuring only known, authorized build agent IP addresses can reach the polling protocol.
Review TeamCity server logs and system process trees for unauthorized command execution or suspicious Java deserialization artifacts, specifically focusing on the agent-to-server communication channel.
"Monitor network traffic for unusual payloads targeting the TeamCity agent polling endpoints. Specifically, look for indicators of Java deserialization (CWE-502) within the agent-server handshake. Use EDR tools to detect suspicious child processes, such as shell executions (cmd.exe, /bin/sh), spawned by the TeamCity service. Additionally, audit the TeamCity 'Authorized Agents' list for any unrecognized agents that may have been registered by an attacker to facilitate code execution."
Experience superior visibility and a simpler approach to cyber risk management