IntelliOS Threat Intel Operating System
IntelliOSPANDAModule|AIFlash Threat Intel Brief

TeamCity CVE-2026-63077 Active Exploitation

Unauthenticated RCE, CI/CD Trust Exposure, and Evidence-Led Response

Active exploitationCISA KEVCVSS 9.8Unauthenticated RCE
Published
Aug 9, 2026
Brief Version
v1.1
Updated
Aug 9, 2026
AI Monitor
Card Library review queue
Brief ID
PANDA-FTIB-TEAMCITY-2026-001
Template
Flash Threat Brief v2.0
  • Understand the product before the vulnerability: JetBrains is a major developer-tools vendor. TeamCity is its CI/CD build-and-deployment orchestration product—the central system that helps transform source code into tested artifacts and software releases. Because it may be trusted by repositories, agents, secrets, signing systems, cloud accounts, and production deployments, compromise can affect the software factory and potentially downstream customers.16, 17
  • This is a live exploitation event: JetBrains confirms reports of active and attempted exploitation against unpatched servers, and CISA added the CVE to KEV on August 5. The August 8 federal due date has passed; unresolved reachable servers require immediate executive visibility.1, 3
  • The entry path needs no credentials: Any attacker who can reach vulnerable TeamCity On-Premises over HTTP(S) may abuse the agent polling protocol to run OS commands as the TeamCity server process. Public reachability and server privilege drive triage priority.1, 2, 4
  • Use the exact vendor hunt signals: Search for com.thoughtworks.xstream.converters.ConversionException; on fixed systems search for com.thoughtworks.xstream.security.ForbiddenClassException; review unauthorized agents, particularly names beginning with scan. Correlate timestamps rather than relying on the displayed agent date.1
  • Patch now, but do not confuse patching with incident closure: Upgrade to 2025.11.7 or 2026.1.3. Use the vendor security patch plugin for 2017.1+ only when immediate upgrade is blocked. Preserve evidence first when safe, restrict reachability, and investigate the vulnerable window.1, 2, 7
  • Automatic does not necessarily mean installed: TeamCity 2024.03 and newer can automatically download security patch plugins and notify administrators, but an administrator still has to review and apply the patch. Full-version automatic upgrades are separately initiated and unsupported for some installation types. Verify the running build or enabled patch; do not rely on an auto-update setting alone.2, 7, 8
  • Scope the software-delivery trust graph: Successful RCE may reach TeamCity data, configuration, stored credentials, artifacts, agents, source repositories, registries, signing systems, clouds, and deployment pipelines. Validate each connected authority and rotate trust where compromise is plausible.1, 2, 8
  • Keep conclusions evidence-bounded: KEV proves exploitation somewhere, not compromise here. Exception messages and scan-prefixed agents warrant investigation but are not standalone proof of success. No reliable issue-specific attacker infrastructure, malware, actor, victim, or ransomware data is public.1, 3, 4

Research and scoping note

For SMBs and MSPs, a single internet-facing TeamCity server may concentrate powerful, shared credentials without long log retention. The closure package should pair technical remediation proof with a dated confidence statement about downstream code, artifact, identity, secret, and deployment integrity.1, 8

JetBrains is a global software company that develops tools used by programmers and engineering teams. TeamCity is JetBrains' continuous integration and continuous delivery platform. A TeamCity server watches source-code repositories for changes, coordinates automated compilation and testing on build agents, collects results, stores or publishes build artifacts, and may authorize later deployment stages. TeamCity On-Premises is installed and managed by the customer; TeamCity Cloud is hosted and protected by JetBrains.16, 17

This function places TeamCity between developers' source code and the software an organization releases. It can be trusted by proprietary repositories, build configurations, API tokens, SSH keys, package registries, artifact repositories, code-signing services, cloud accounts, deployment credentials, and production environments. A compromise can therefore steal intellectual property or secrets, alter build instructions or outputs, implant malicious code into trusted artifacts, reach connected infrastructure, or create downstream risk for customers. These are plausible impact paths; a specific incident requires local evidence.2, 8, 16

The status is now materially different from initial disclosure. JetBrains's August 7 follow-up says it received reports of active exploitation and attempted exploitation targeting unpatched TeamCity servers. CISA had added CVE-2026-63077 to the Known Exploited Vulnerabilities catalog on August 5 and assigned an August 8 required-action date. The original July 27 statement that JetBrains was then unaware of exploitation is retained only as a dated historical fact.1, 2, 3

CVE-2026-63077 affects TeamCity On-Premises servers reachable over HTTP or HTTPS. An unauthenticated attacker can abuse the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating-system commands with the privileges of the TeamCity server process. No user action is required. The JetBrains CNA scores it CVSS 3.1 9.8 Critical and maps it to CWE-502, Deserialization of Untrusted Data; NVD had not supplied an independent score at the cutoff.1, 2, 4, 5, 6

TeamCity is a CI/CD control plane, so host compromise can cross multiple trust boundaries. JetBrains says a successful exploit could expose TeamCity data, configuration, and stored credentials, modify server state, and potentially compromise build artifacts and downstream pipelines. In a particular environment, the actual blast radius follows the server process account, repository and registry tokens, signing material, deployment credentials, build-agent relationships, and accessible secrets. Those are investigation hypotheses until local evidence establishes use or change.1, 2, 8

JetBrains now supplies concrete hunt signals. Administrators should search TeamCity server logs for com.thoughtworks.xstream.converters.ConversionException, which may indicate an attempted or successful exploit but does not confirm either. Systems already upgraded or protected by the plugin may record com.thoughtworks.xstream.security.ForbiddenClassException when an exploit attempt was successfully blocked. Administrators should also review unauthorized build agents for unexpected names beginning with scan and use relevant log timestamps, not the unauthorized-agent display date, to build the timeline.1

The fixed releases are TeamCity 2025.11.7 and 2026.1.3. JetBrains also provides a security patch plugin for TeamCity 2017.1 and later if immediate upgrade is impossible. Versions 2017.1 through 2018.1 require a restart after plugin installation; from 2018.2 the plugin can be enabled without restart. The plugin addresses this CVE only, so a supported full upgrade remains the preferred durable state. TeamCity Cloud customers need no action, and JetBrains says it found no Cloud exploitation through this issue.1, 2, 7

Administrators must not treat automatic update settings as proof of remediation. TeamCity 2024.03 and newer can automatically download available security patch plugins and notify administrators, but a system administrator must review and apply the pending patch. Full-version automatic update is a separate, administrator-controlled process and is unavailable for some installations, including Docker. Protection must be proven with the exact running version or active security patch plugin.2, 7, 8

A reachable server that was vulnerable during the exploitation window requires more than a patch ticket. Preserve TeamCity, reverse-proxy, firewall, system, EDR, identity, VCS, artifact, registry, signer, secret-store, deployment, and build-agent telemetry; record the pre-change build; restrict reachability; remediate; validate the new runtime; and hunt the vulnerable period. If command execution or unexplained privileged CI/CD changes appear, move into incident response, rotate reachable trust, validate artifacts and releases from known-good inputs, and rebuild when integrity cannot be established.1, 3, 7, 8

SMBs may have limited staff, short retention, and a TeamCity service identity with broad shared privileges. MSPs face an additional concentration risk: one management pattern may touch multiple customer environments, yet evidence must remain customer- and server-specific. Insurers and counsel should request the inventory, exposure interval, remediation proof, preserved evidence, confirmed access, affected trust paths, recovery actions, and remaining uncertainty rather than accepting a statement that the product was simply patched.1, 3, 8

The public record does not provide reliable issue-specific attacker IP addresses, domains, malicious URLs, filenames, file hashes, named actors, victim identities, campaign scale, or successful-impact counts. CISA lists ransomware use as unknown. Public exploit status is not established by the retained primary sources. These absences prohibit blocklist invention and attribution; they do not lower response urgency or prove that no such information exists privately.1, 3, 4

Research and scoping note

Confidence is high for the vulnerability, product scope, exploit precondition, fixed versions, current exploitation status, and vendor-published hunt signals. Confidence is intentionally withheld for local compromise, actor, victim, malware, ransomware, and downstream impact until issue-specific or owned evidence supports them.1, 2, 3, 4