CISA Warns of TeamCity RCE Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

The U.S. Cybersecurity and Infrastructure Security Agency has warned that a critical JetBrains TeamCity flaw is being actively exploited. The vulnerability, tracked as CVE-2026-63077, can let an unauthenticated attacker run code remotely on vulnerable TeamCity On-Premises servers.

CISA added the issue to its Known Exploited Vulnerabilities catalog on August 5 and set an August 8 remediation deadline for affected federal civilian agencies.

TeamCity is a continuous integration and continuous delivery platform used to build, test, and deploy software. A compromise of its central server can create serious supply-chain risk.

Attackers may gain access to source code, build settings, stored secrets, signing material, and deployment connections. They could also alter build outputs or use the server as a foothold into a wider network.

The weakness is categorized as CWE-502, deserialization of untrusted data. It is part of the TeamCity agent polling protocol, which supports communication between build agents and the TeamCity server.

TeamCity RCE Vulnerability Exploited

According to the vulnerability description, a remote attacker with HTTP or HTTPS access can exploit the flaw to bypass authentication checks and execute operating system commands with the privileges of the TeamCity server process. No valid account is required.

JetBrains said all TeamCity On-Premises versions were affected before the security fixes. The company released patched versions 2025.11.7 and 2026.1.3.

Organizations that cannot upgrade immediately can use JetBrains’ security patch plugin on TeamCity 2017.1 and later. However, the plugin addresses only this vulnerability, so a full update remains the preferred long-term response.

TeamCity Cloud customers do not need to take any action, as the vendor has already implemented the required protections. CISA’s alert increases the urgency because it confirms exploitation in real attacks.

The agency has not publicly identified ransomware use for this specific issue, and its catalog entry lists that status as unknown. Even so, exposed CI/CD systems are high-value targets.

Threat actors have repeatedly targeted TeamCity vulnerabilities to obtain initial access, steal credentials, and move laterally across enterprise environments.

Administrators should first identify every TeamCity On-Premises installation, including development, testing, and disaster-recovery systems.

They should urgently update to a fixed release or deploy the vendor patch where an upgrade cannot be completed before the deadline. Security teams should restrict TeamCity access to trusted users, agents, and networks, removing unnecessary public exposure.

They should also review server and web logs for unusual agent polling activity, unexpected administrator actions, unfamiliar plugins, new accounts, and suspicious command execution.

Organizations should preserve relevant logs and system evidence before making major changes if compromise is suspected. They should rotate credentials, tokens, certificates, and other secrets stored or accessible through the platform, then inspect recent builds and release artifacts for unauthorized changes.

CISA also advises stakeholders to assess each asset’s internet exposure and follow its risk-based patching and forensic triage requirements.

Fast remediation is essential: unauthenticated remote code execution on a build server can quickly escalate into a full software supply chain incident. Monitoring should continue after remediation is complete.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.