Threat reportVulnerabilityTL-2026-1747
CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol
CVE-2026-63077 (TL-2026-1747) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-28 and last reviewed 2026-09-06. It has no confirmed attribution, affects JetBrains TeamCity On-Premises, references 1 CVE (CVE-2026-63077), maps to 75 MITRE ATT&CK techniques (T1003, T1003.001, T1005), and is covered by 9 detection rules and 93 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 75MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 93Indicators of compromise
Key facts for TL-2026-1747
- Threat ID
- TL-2026-1747
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- software-development, technology, government administration, financial-services, defense-industrial-base, critical-infrastructure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 93
- Updates
- 2026-09-06 · 8 updates · revalidated 8× · latest source
Malware and tooling in CVE-2026-63077
Malware and tooling: Cobalt Strike, Forest64.exe, GraphDrop, Jasmin Ransomware, Metasploit teamcity_agent_xmlrpc_exec module
How CVE-2026-63077 works
JetBrains patched a critical unauthenticated remote code execution vulnerability (CVE-2026-63077, CVSS 9.8) in TeamCity On-Premises, rooted in insecure deserialization of untrusted data (CWE-502) in the build-agent polling protocol. A remote attacker with no credentials can send a crafted payload to the exposed agent communication channel and execute OS commands with the privileges of the TeamCity server process, exposing source code, build secrets, and CI/CD pipeline integrity. All On-Premises versions before 2025.11.7 and 2026.1.3 are affected; JetBrains reports no active exploitation as of the July 27, 2026 advisory, though TeamCity has a well-documented history as a nation-state and ransomware target.
CVE-2026-63077 is a critical (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) unauthenticated remote code execution vulnerability affecting all JetBrains TeamCity On-Premises versions prior to 2025.11.7 and 2026.1.3. The root cause is insecure deserialization of untrusted data (CWE-502) in TeamCity's agent polling protocol — the unidirectional channel build agents use by default to poll the server for jobs and configuration (governed by the server-side `teamcity.agent.communicationProtocols` property, which defaults to `polling,xml-rpc`). An attacker with only HTTP(S) network reachability to a TeamCity server can submit a crafted payload to this channel with zero authentication and zero user interaction, triggering deserialization of attacker-controlled data and achieving arbitrary OS command execution under the TeamCity server process's privileges. JetBrains' own impact assessment states successful exploitation 'could expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines' — i.e., a direct software-supply-chain compromise vector, since anything the TeamCity server can build or sign, an attacker with RCE on that server can tamper with.
The vulnerability was privately reported by security researcher Antoni Tremblay on July 10, 2026, under JetBrains' coordinated disclosure policy, and patched in the July 27, 2026 advisory. Independent reporting from Help Net Security, The Hacker News, and Cyber Security News on July 28, 2026 corroborated the vendor's technical description without adding new mechanics. JetBrains states it checked TeamCity Cloud (unaffected — this is an On-Premises-only flaw) for signs of exploitation and found none, and that as of publication it is 'not aware of any active exploitation.' No public proof-of-concept exploit code was located during this research, and CVE-2026-63077 does not currently appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. One third-party vendor page (IONIX threat center) states it is 'tracking ongoing exploitation attempts' for this CVE, but this claim is unverified, uncorroborated by any other source, and directly conflicts with JetBrains' official statement — it should be treated as a low-confidence signal pending confirmation, not evidence of in-the-wild activity.
While CVE-2026-63077 itself has no confirmed exploitation, TeamCity On-Premises has a strong and repeated history as a high-value CI/CD attack surface. CVE-2023-42793 (authentication bypass RCE) was exploited at scale by Russia's APT29/Midnight Blizzard/Cozy Bear (SVR) and by North Korea's Diamond Sleet (Lazarus/Hidden Cobra/ZINC) and Onyx Sleet (Andariel/Plutonium), the latter pair deploying the Forest64.exe persistence/credential-dumping tool and malware behaviorally consistent with APT29's GraphicalProton backdoor (Microsoft, October 2023). CVE-2024-27198/27199 (authentication bypass via `;.jsp` path confusion against `/app/rest/users`) was exploited within hours of disclosure to create rogue administrator accounts, and at least one intrusion escalated to a Cobalt Strike beacon (delivered as `java64.exe` via Base64-encoded PowerShell) and Jasmin ransomware deployment (Trend Micro, 2024). Cyber Security News' own coverage of this advisory references BianLian as a prior exploiter of exposed TeamCity servers. This precedent — admin-account creation, credential/token theft, Cobalt Strike staging, and ransomware follow-on — is the threat model defenders should hunt against if CVE-2026-63077 transitions from theoretical to actively exploited, even though no such transition has been confirmed for this specific CVE at time of writing.
Mitigation is straightforward: upgrade to 2025.11.7 or 2026.1.3, or apply JetBrains' security patch plugin (available back to 2017.1) if an immediate upgrade is not feasible. JetBrains additionally recommends restricting TeamCity server and agent-communication access to trusted networks or a VPN, running the server process with minimum required privileges, and hosting the server separately from build agents to reduce blast radius if either is compromised.
MITRE ATT&CK techniques used in TL-2026-1747
Credential Access
T1003 OS Credential Dumping; T1003.001 LSASS Memory; T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1552.004 Private Keys; T1552.005 Cloud Instance Metadata API; T1555 Credentials from Password Stores
Collection
T1005 Data from Local System; T1074 Data Staged; T1213 Data from Information Repositories; T1213.003 Data from Information Repositories: Code Repositories; T1530 Data from Cloud Storage; T1560.001 Archive Collected Data: Archive via Utility
Lateral Movement
T1021 Remote Services; T1021.001 Remote Desktop Protocol; T1210 Exploitation of Remote Services; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1036.004 Masquerade Task or Service; T1036.005 Masquerading: Match Legitimate Name or Location; T1070 Indicator Removal; T1070.004 Indicator Removal: File Deletion; T1140 Deobfuscate/Decode Files or Information; T1202 Indirect Command Execution; T1211 Exploitation for Defense Evasion; T1574.001 DLL
Exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol; T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service
Persistence
T1053 Scheduled Task/Job; T1053.005 Scheduled Task; T1098 Account Manipulation; T1136 Create Account; T1136.001 Local Account; T1505 Server Software Component; T1505.003 Server Software Component: Web Shell; T1543 Create or Modify System Process
Discovery
T1057 Process Discovery; T1069 Permission Groups Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1518 Software Discovery; T1526 Cloud Service Discovery
Execution
T1059 Command and Scripting Interpreter; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.004 Unix Shell
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts
Command and Control
T1071.001 Web Protocols; T1090 Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1572 Protocol Tunneling
defense-impairment
T1112 Modify Registry; T1553.002 Code Signing; T1685 Disable or Modify Tools
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1195.003 Supply Chain Compromise: Compromise Software Supply Chain; T1199 Trusted Relationship
initial-access
T1195.002 Compromise Software Supply Chain
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1565.001 Stored Data Manipulation
Resource Development
T1583.001 Domains; T1587.004 Develop Capabilities: Exploits; T1588.005 Exploits
Reconnaissance
T1592 Gather Victim Host Information; T1595 Active Scanning; T1595.002 Vulnerability Scanning
Affected products and versions in CVE-2026-63077
- JetBrains — TeamCity On-Premises
Vulnerable versions: all versions prior to 2025.11.7 (2025.11.x branch); all versions prior to 2026.1.3 (2026.x branch)
Fixed in: 2025.11.7; 2026.1.3
Remediation for CVE-2026-63077
Patches
- JetBrains TeamCity On-Premises 2025.11.7
- JetBrains TeamCity On-Premises 2026.1.3
- JetBrains security patch plugin for 2017.1+ (auto-installs on 2024.03+; 2017.1-2018.1 requires a server restart after installation; 2018.2+ can enable the patch without restart)
Immediate actions
- Restrict network access to the TeamCity On-Premises server and its build-agent communication channel to trusted internal IP ranges or a VPN; do not expose it directly to the internet.
- If immediate upgrade is not possible, apply the JetBrains security patch plugin (available for 2017.1+).
Workarounds
- Require VPN or an additional access-control layer in front of internet-facing TeamCity instances.
- Restrict the agent communication protocol/port to trusted build-agent IP ranges only.
Longer-term hardening
- Upgrade to TeamCity On-Premises 2025.11.7 or 2026.1.3 (or later).
- Host the TeamCity server and build agents on network segments isolated from the general corporate network to limit blast radius if either is compromised.
- Run the TeamCity server process with the minimum required OS privileges.
- Monitor the CISA KEV catalog and vendor advisories for confirmation of active exploitation and re-prioritize patch urgency accordingly.
CVEs associated with CVE-2026-63077
Weaknesses (CWE) in CVE-2026-63077
Timeline of CVE-2026-63077
Showing the 20 most recent tracked events.
- Help Net Security, The Hacker News, and Cyber Security News publish independent coverage corroborating the vendor advisory and noting TeamCity's history as a CI/CD attack target.
- Penligent HackingLabs analysis highlights that JetBrains' advisory explicitly states the CWE-502 classification alone does not confirm use of any known public Java deserialization gadget chain, and details a realistic post-RCE progression through discovery, credential harvesting, control-plane manipulation, and downstream artifact tampering.
- Penligent and Rescana publish deeper technical/risk analyses of CVE-2026-63077, framing its CI/CD supply-chain blast radius and citing TeamCity's exploitation history as grounds to prioritize patch/detection readiness ahead of confirmed exploitation.
- BleepingComputer publishes coverage noting this is the third critical TeamCity RCE in three years and highlighting the platform's history of exploitation by ransomware gangs and North Korean state-backed actors.
- Censys publishes analysis identifying ~4,500 internet-exposed TeamCity instances, with only ~450 (10%) running patched versions.
- FOFA highlights over 143,000 internet-exposed hosts matching the JetBrains TeamCity fingerprint (app="JET_BRAINS-TeamCity"), quantifying a large potential attack surface for unpatched deployments.
- GBHackers publishes further coverage of CVE-2026-63077. As of this date no public PoC exists, no active exploitation is confirmed, and the CVE remains absent from the CISA KEV catalog.
- SecurityIntel newsletter and threat intelligence sources flag CVE-2026-63077 as exploited in the wild.
- CISA adds CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, confirming active exploitation; federal agencies required to remediate under BOD 26-04 by 2026-08-08.
- Cybersecurity News publishes detailed coverage of active exploitation; IONIX threat intelligence separately reports tracking active exploitation attempts. Multiple additional vendor analyses (Penligent, Falcon Internet) are published.
- SecurityWeek reports active exploitation underway; notes no public PoC or threat actor attribution available at this time.
- JetBrains itself confirms active exploitation of CVE-2026-63077 in the wild (distinct from third-party media reports of active exploitation on 2026-08-06).
- Rapid7 publishes a full technical root-cause analysis of the three-stage XStream gadget chain, alongside a public proof-of-concept exploit script (sfewer-r7/CVE-2026-63077) on GitHub automating the registration-to-webshell chain.
- Threat actors begin exploiting CVE-2026-63077 against JetBrains' own Cadence cloud computing service (api.cadence.jetbrains.com).
- CISA BOD 26-04 remediation deadline for U.S. federal civilian agencies, a three-day window from the 2026-08-05 KEV addition reflecting the urgency of active exploitation against a critical CI/CD vulnerability.
- JetBrains discovers the exploitation activity on the Cadence server after 16 days of attacker access.
- JetBrains takes the affected Cadence server offline and begins incident response.
- JetBrains confirms a full 2024 Cadence server backup (credentials, AWS IAM secrets, configuration) plus current user PII and S3 bucket data were accessed; no additional current-data extraction found at that point.
- JetBrains concludes its Cadence security investigation.
- The Hacker News publishes a detailed report on the Cadence breach, documenting six exploitation IP addresses.
Update history for TL-2026-1747
- 2026-09-06 — Attackers Breached JetBrains Cadence Cloud Computing Service via Unpatched CVE-2026-63077: What changed No field escalation was required — exploitability, status, and severity were already ACTIVE/ACTIVE/CRITICAL for this CVE. What changed is that the tracked risk materialized: attackers used CVE-2026-63077 to breach JetBrains' ow
- 2026-08-09 — CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity via Unsafe XStream Deserialization: What changed No field escalation: exploitability (ACTIVE), severity (CRITICAL), and status (ACTIVE) in the existing record already match this report's findings from the prior 2026-08-05/06 KEV/active-exploitation revalidations. What changed
- 2026-08-06 — CVE-2026-63077 — JetBrains TeamCity On-Premises Critical Authentication Bypass via Deserialization Leading to Remote Code Execution: What changed No change to severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), CVSS (9.8), or attribution (Unattributed/LOW) — the existing record already carries these values from a prior revalidation. New indicators (5) 3 new it
- 2026-08-06 — CVE-2026-63077 — Actively Exploited Unauthenticated RCE in JetBrains TeamCity via Agent Polling Protocol Deserialization: What changed No severity/exploitability/status change — the record is already CRITICAL/ACTIVE from the prior CISA KEV revalidation. This report deepens attribution and TTP coverage: Storm-1175 (a Medusa ransomware affiliate) and Kimsuky are
- 2026-08-06 — Active exploitation of CVE-2026-63077 — JetBrains TeamCity On-Premises unauthenticated deserialization RCE (CISA KEV): What changed Exploitability THEORETICAL → ACTIVE: CISA added CVE-2026-63077 to its KEV catalog on 2026-08-05, confirming in-the-wild exploitation (federal remediation deadline 2026-08-08 under BOD 26-04). Severity (CRITICAL) and CVSS (9.8)
- 2026-08-02 — CVE-2026-63077: Critical Unauthenticated Remote Code Execution in JetBrains TeamCity via Agent Polling Protocol Deserialization: What changed No change to severity (CRITICAL), exploitability (THEORETICAL), status, CVSS (9.8), or attribution (LOW/Unknown) — no confirmed exploitation in either report. New indicators (9) FOFA fingerprint quantifying 143K+ exposed TeamCi
- 2026-07-31 — CVE-2026-63077: JetBrains TeamCity On-Premises Authentication Bypass via Agent Polling Protocol Enables Unauthenticated RCE: What changed No change to severity, exploitability, status, CVSS, or attribution — still CRITICAL / CVSS 9.8 / THEORETICAL, no confirmed active exploitation, no public PoC, absent from CISA KEV. New procedural facts: CISA attached SSVC deci
- 2026-07-31 — CVE-2026-63077: Critical Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol Deserialization: What changed No field escalation: severity remains CRITICAL, exploitability remains THEORETICAL, status remains ACTIVE, attribution remains Unattributed/LOW as of 2026-07-31 — vendor and independent researchers still report no confirmed act
Sources cited for CVE-2026-63077
- Critical Security Issue Affecting TeamCity On-Premises (CVE-2026-63077) – Update to 2025.11.7 or 2026.1.3 Now
- JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
- JetBrains Patch TeamCity Flaw
- CVE-2026-63077 – Unauthenticated RCE via Agent Polling Protocol
- NVD - CVE-2026-63077
- Multiple North Korean threat actors exploiting the TeamCity CVE-2023-42793 vulnerability
- TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types
- Security Insights: JetBrains TeamCity CVE-2024-27198 and CVE-2024-27199
- TeamCity Intrusion Saga: APT29 Suspected Among the Attackers Exploiting CVE-2023-42793
- CVE-2023-42793: CozyBear Targets Software Developers Exploiting JetBrains TeamCity
- TeamCity Agent XML-RPC Command Execution — Metasploit Module
- CVE-2023-42793 Vulnerability in TeamCity: Post-Mortem
- JetBrains TeamCity Multiple Authentication Bypass Vulnerabilities (CVE-2024-27198/CVE-2024-27199)
- CISA Adds One Known Exploited JetBrains Vulnerability, CVE-2024-27198, to Catalog
Detection coverage for TL-2026-1747
As of 2026-09-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1747 across Splunk SPL, Microsoft KQL and Sigma, covering 93 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.