# CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity On-Premises via Agent Polling Protocol

> JetBrains patched a critical unauthenticated remote code execution vulnerability (CVE-2026-63077, CVSS 9.8) in TeamCity On-Premises, rooted in insecure deserialization of untrusted data (CWE-502) in the build-agent polling protocol. A remote attacker with no credentials can send a crafted payload to the exposed agent communication channel and execute OS commands with the privileges of the TeamCity server process, exposing source code, build secrets, and CI/CD pipeline integrity. All On-Premises versions before 2025.11.7 and 2026.1.3 are affected; JetBrains reports no active exploitation as of the July 27, 2026 advisory, though TeamCity has a well-documented history as a nation-state and ransomware target.

- **Published:** 2026-07-28T00:00:00Z
- **Last reviewed:** 2026-09-06T18:00:56.302Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1747
- **ID:** TL-2026-1747
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 93 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-63077

## Description

CVE-2026-63077 is a critical (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) unauthenticated remote code execution vulnerability affecting all JetBrains TeamCity On-Premises versions prior to 2025.11.7 and 2026.1.3. The root cause is insecure deserialization of untrusted data (CWE-502) in TeamCity's agent polling protocol — the unidirectional channel build agents use by default to poll the server for jobs and configuration (governed by the server-side `teamcity.agent.communicationProtocols` property, which defaults to `polling,xml-rpc`). An attacker with only HTTP(S) network reachability to a TeamCity server can submit a crafted payload to this channel with zero authentication and zero user interaction, triggering deserialization of attacker-controlled data and achieving arbitrary OS command execution under the TeamCity server process's privileges. JetBrains' own impact assessment states successful exploitation 'could expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines' — i.e., a direct software-supply-chain compromise vector, since anything the TeamCity server can build or sign, an attacker with RCE on that server can tamper with.

The vulnerability was privately reported by security researcher Antoni Tremblay on July 10, 2026, under JetBrains' coordinated disclosure policy, and patched in the July 27, 2026 advisory. Independent reporting from Help Net Security, The Hacker News, and Cyber Security News on July 28, 2026 corroborated the vendor's technical description without adding new mechanics. JetBrains states it checked TeamCity Cloud (unaffected — this is an On-Premises-only flaw) for signs of exploitation and found none, and that as of publication it is 'not aware of any active exploitation.' No public proof-of-concept exploit code was located during this research, and CVE-2026-63077 does not currently appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. One third-party vendor page (IONIX threat center) states it is 'tracking ongoing exploitation attempts' for this CVE, but this claim is unverified, uncorroborated by any other source, and directly conflicts with JetBrains' official statement — it should be treated as a low-confidence signal pending confirmation, not evidence of in-the-wild activity.

While CVE-2026-63077 itself has no confirmed exploitation, TeamCity On-Premises has a strong and repeated history as a high-value CI/CD attack surface. CVE-2023-42793 (authentication bypass RCE) was exploited at scale by Russia's APT29/Midnight Blizzard/Cozy Bear (SVR) and by North Korea's Diamond Sleet (Lazarus/Hidden Cobra/ZINC) and Onyx Sleet (Andariel/Plutonium), the latter pair deploying the Forest64.exe persistence/credential-dumping tool and malware behaviorally consistent with APT29's GraphicalProton backdoor (Microsoft, October 2023). CVE-2024-27198/27199 (authentication bypass via `;.jsp` path confusion against `/app/rest/users`) was exploited within hours of disclosure to create rogue administrator accounts, and at least one intrusion escalated to a Cobalt Strike beacon (delivered as `java64.exe` via Base64-encoded PowerShell) and Jasmin ransomware deployment (Trend Micro, 2024). Cyber Security News' own coverage of this advisory references BianLian as a prior exploiter of exposed TeamCity servers. This precedent — admin-account creation, credential/token theft, Cobalt Strike staging, and ransomware follow-on — is the threat model defenders should hunt against if CVE-2026-63077 transitions from theoretical to actively exploited, even though no such transition has been confirmed for this specific CVE at time of writing.

Mitigation is straightforward: upgrade to 2025.11.7 or 2026.1.3, or apply JetBrains' security patch plugin (available back to 2017.1) if an immediate upgrade is not feasible. JetBrains additionally recommends restricting TeamCity server and agent-communication access to trusted networks or a VPN, running the server process with minimum required privileges, and hosting the server separately from build agents to reduce blast radius if either is compromised.

## MITRE ATT&CK

- T1595 Active Scanning
- T1592 Gather Victim Host Information
- T1588.005 Exploits
- T1583.001 Domains
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1136 Create Account
- T1136.001 Local Account
- T1098 Account Manipulation
- T1068 Exploitation for Privilege Escalation
- T1078 Valid Accounts
- T1070 Indicator Removal
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1552.001 Credentials In Files
- T1003 OS Credential Dumping
- T1082 System Information Discovery
- T1518 Software Discovery
- T1210 Exploitation of Remote Services
- T1005 Data from Local System
- T1074 Data Staged
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1486 Data Encrypted for Impact
- T1195.002 Compromise Software Supply Chain
- T1053.005 Scheduled Task
- T1036.004 Masquerade Task or Service
- T1574.001 DLL
- T1003.001 LSASS Memory
- T1090 Proxy
- T1021.001 Remote Desktop Protocol
- T1565.001 Stored Data Manipulation
- T1595.002 Vulnerability Scanning
- T1059.003 Windows Command Shell
- T1059.004 Unix Shell
- T1543 Create or Modify System Process
- T1505 Server Software Component
- T1555 Credentials from Password Stores

## Sources

- [Critical Security Issue Affecting TeamCity On-Premises (CVE-2026-63077) – Update to 2025.11.7 or 2026.1.3 Now](https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/)
- [JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)](https://www.helpnetsecurity.com/2026/07/28/teamcity-rce-cve-2026-63077-fixed/)
- [Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In](https://thehackernews.com/2026/07/critical-teamcity-flaw-could-let.html)
- [JetBrains Patch TeamCity Flaw](https://cybersecuritynews.com/jetbrains-patch-teamcity-flaw/)
- [CVE-2026-63077 – Unauthenticated RCE via Agent Polling Protocol](https://www.ionix.io/threat-center/cve-2026-63077/)
- [NVD - CVE-2026-63077](https://nvd.nist.gov/vuln/detail/CVE-2026-63077)
- [Multiple North Korean threat actors exploiting the TeamCity CVE-2023-42793 vulnerability](https://www.microsoft.com/en-us/security/blog/2023/10/18/multiple-north-korean-threat-actors-exploiting-the-teamcity-cve-2023-42793-vulnerability/)
- [TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types](https://www.trendmicro.com/en_us/research/24/c/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware.html)
- [Security Insights: JetBrains TeamCity CVE-2024-27198 and CVE-2024-27199](https://www.splunk.com/en_us/blog/security/security-insights-jetbrains-teamcity-cve-2024-27198-and-cve-2024-27199.html)
- [TeamCity Intrusion Saga: APT29 Suspected Among the Attackers Exploiting CVE-2023-42793](https://www.fortinet.com/blog/threat-research/teamcity-intrusion-saga-apt29-suspected-exploiting-cve-2023-42793)
- [CVE-2023-42793: CozyBear Targets Software Developers Exploiting JetBrains TeamCity](https://www.picussecurity.com/resource/blog/cve-2023-42793-cozybear-targets-software-developers-exploiting-jetbrains-teamcity)
- [TeamCity Agent XML-RPC Command Execution — Metasploit Module](https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/misc/teamcity_agent_xmlrpc_exec.rb)
- [CVE-2023-42793 Vulnerability in TeamCity: Post-Mortem](https://blog.jetbrains.com/teamcity/2023/09/cve-2023-42793-vulnerability-post-mortem/)
- [JetBrains TeamCity Multiple Authentication Bypass Vulnerabilities (CVE-2024-27198/CVE-2024-27199)](https://www.rapid7.com/blog/post/2024/03/04/etr-cve-2024-27198-and-cve-2024-27199-jetbrains-teamcity-multiple-authentication-bypass-vulnerabilities-fixed/)
- [CISA Adds One Known Exploited JetBrains Vulnerability, CVE-2024-27198, to Catalog](https://www.cisa.gov/news-events/alerts/2024/03/07/cisa-adds-one-known-exploited-jetbrains-vulnerability-cve-2024-27198-catalog)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1747
