Executive Summary
A critical vulnerability, CVE-2026-63077, has been identified in JetBrains TeamCity On-Premises that allows unauthenticated attackers to execute arbitrary operating system commands without logging in. This flaw, which carries a CVSS score of 9.8, affects all versions of TeamCity On-Premises prior to 2025.11.7 and 2026.1.3. The vulnerability is particularly severe because it enables remote code execution (RCE) over HTTP(S) without any authentication, potentially granting attackers full control over the affected server. JetBrains has released security updates and a patch plugin to remediate the issue. As of the time of writing, there is no evidence of exploitation in the wild, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Organizations using TeamCity On-Premises are strongly urged to update immediately to mitigate the risk.
Technical Information
CVE-2026-63077 is a critical unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises. The flaw resides in the agent polling protocol, which is responsible for communication between build agents and the TeamCity server. Due to improper authentication checks, an attacker can send specially crafted HTTP or HTTPS requests to the TeamCity server, bypassing authentication and triggering arbitrary OS command execution with the privileges of the TeamCity server process.
The technical exploitation flow involves the attacker crafting requests that exploit the agent polling protocol endpoint. Because the vulnerability does not require authentication, any actor with network access to the TeamCity server can exploit it. Successful exploitation allows the attacker to execute arbitrary commands, potentially leading to the exposure of sensitive data, theft of credentials, modification of build configurations, and compromise of the CI/CD pipeline. The attacker could also use the compromised server as a foothold for lateral movement within the network or to deploy additional malware.
The vulnerability affects all TeamCity On-Premises versions prior to 2025.11.7 and 2026.1.3. TeamCity Cloud is not affected, as JetBrains has already applied the necessary fixes to its managed service.
Exploitation in the Wild
As of the publication of this advisory, there is no evidence of exploitation in the wild for CVE-2026-63077. No public proof-of-concept exploit code has been observed on major repositories, and no threat intelligence sources have reported active exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and there are no confirmed incidents of compromise attributed to this flaw. However, due to the critical nature of the vulnerability and the history of rapid exploitation of similar flaws in CI/CD platforms, organizations should assume that exploitation attempts may occur soon after public disclosure.
APT Groups using this vulnerability
There are currently no reports or intelligence linking any Advanced Persistent Threat (APT) groups or other threat actors to the exploitation of CVE-2026-63077. No sector-specific or country-specific targeting has been observed. This may change rapidly if public exploit code becomes available or if opportunistic attackers begin scanning for vulnerable TeamCity On-Premises instances.
Affected Product Versions
The following product versions are affected by CVE-2026-63077: all releases of JetBrains TeamCity On-Premises prior to 2025.11.7 and 2026.1.3. This includes every version from the initial release up to, but not including, the fixed versions. TeamCity Cloud is not affected. JetBrains has also released a security patch plugin for versions 2017.1 and newer, allowing organizations unable to upgrade immediately to mitigate the vulnerability.
Workaround and Mitigation
The primary remediation is to upgrade TeamCity On-Premises to version 2025.11.7 or 2026.1.3 as soon as possible. If immediate upgrade is not feasible, organizations should apply the official security patch plugin provided by JetBrains for versions 2017.1 and newer. In addition, it is strongly recommended to restrict network access to the TeamCity server, ensuring it is only accessible from trusted networks and not exposed to the public internet. Administrators should also avoid exposing TeamCity login screens or REST APIs externally. Regularly monitor server logs for unusual activity, such as unexpected outbound connections or unauthorized changes to build configurations.
Indicators of Compromise
The following caveat applies: Indicators of Compromise (IOCs) are point-in-time and should be validated before enforcement. At the time of writing, no public indicators of compromise have been published for CVE-2026-63077 due to the absence of confirmed exploitation cases. Organizations are advised to monitor for general signs of compromise, such as unusual outbound connections from the TeamCity server, unexpected processes spawned by the TeamCity server process, and unauthorized changes to build configurations or artifacts.
No public indicators of compromise were available at the time of writing.
References
Rescana is here for you
Rescana provides a comprehensive Third-Party Risk Management (TPRM) platform that empowers organizations to continuously monitor, assess, and mitigate cyber risks across their supply chain. Our platform leverages advanced automation and threat intelligence to deliver actionable insights, helping you stay ahead of emerging threats and regulatory requirements. We are happy to answer any questions at info@rescana.com.



