Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

JetBrains TeamCity Unauthenticated RCE (CVE-2026-63077)

Historical catalog analysis: CISA added this entry on August 05, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. Check current vendor guidance before acting.

What the vulnerability is

CVE-2026-63077 is a deserialization of untrusted data vulnerability (CWE-502) affecting JetBrains TeamCity. The flaw allows an unauthenticated attacker to achieve remote code execution (RCE) by leveraging the agent polling protocol. Due to its potential for impact, CISA added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog on August 5, 2026.

Exposure and applicability

This vulnerability applies to deployments of JetBrains TeamCity that utilize the agent polling protocol. The primary exposure path is through the network interface used by build agents to communicate with the TeamCity server. Organizations with internet-facing TeamCity instances are at higher risk, as the exploit does not require prior authentication to execute code on the host system.

Remediation priorities

Based on the inclusion of this flaw in the CISA KEV catalog, remediation should be prioritized for all active installations. Our analysis suggests the following priority sequence:

  1. Immediate Patching: Apply mitigations and updates as specified by JetBrains vendor instructions. This is the primary method to address the underlying deserialization flaw.
  2. Exposure Reduction: Evaluate the internet exposure of TeamCity assets. In accordance with BOD 26-04 guidance, instances exposed to the public internet should be prioritized for immediate remediation or isolated from untrusted networks.
  3. Forensic Triage: For organizations that identify vulnerable, internet-exposed assets, we recommend performing forensic triage to determine if the vulnerability was exploited prior to patching, following CISA’s forensics triage requirements.

How to validate remediation

Verification must move beyond simple version checks to ensure the exposure is actually reduced. Defenders should employ the following validation methods:

  • Configuration Audit: Verify that the mitigations prescribed by JetBrains are active and correctly configured across all server nodes.
  • Network Validation: Confirm via firewall logs or network scanning that the agent polling protocol is not accessible from unauthorized or public IP addresses, limiting the attack surface to known build agents.
  • Integrity Check: Perform a forensic review of system logs for anomalous activity associated with the agent polling protocol during the window of exposure.

Limits and open questions

While patching addresses the vulnerability, residual risk remains if an attacker has already established persistence on the server. A deployed fix prevents new exploitation attempts but does not remove existing unauthorized access. It remains unknown whether this vulnerability is currently being leveraged by ransomware campaigns. Furthermore, while CISA has set a remediation deadline of August 8, 2026, for federal agencies, non-federal organizations must determine their own timelines based on their specific risk profile and asset exposure.

Source and editorial note

CVE-2026-63077: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Source date: August 05, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Archive date: August 08, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 04, 2026 at 00:08 UTC.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment