Threat Bulletins TLP WHITE: Update: Critical Remote Code Execution Vulnerability in JetBrains TeamCity On-Premises (CVE-2026-63077)

JetBrains has released security fixes for an unauthenticated remote code execution vulnerability (CVE-2026-63077) affecting all customer-managed TeamCity On-Premises installations. 

The flaw allows remote attackers with network access over HTTP or HTTPS to bypass authentication checks and execute arbitrary operating system commands on the underlying server. While JetBrains has already automatically patched its fully managed cloud service, administrators responsible for self-hosted customer-managed servers must apply software updates or install the security patch plugin.

Health-ISAC provides this information to increase situational awareness and encourage organizations to assess their risk exposure to this vulnerability.

Update (as of September 28, 2026): Ransomware groups are now exploiting this critical vulnerability. Meanwhile, security threat watchdog Shadowserver is still tracking over 160 TeamCity servers that are unpatched against the flaw.

Additional Info

Analysis:

CVE-2026-63077 is an unauthenticated authentication bypass flaw in the TeamCity agent polling protocol for servers reachable via HTTP or HTTPS. A third-party security researcher privately reported the vulnerability to JetBrains on July 10, 2026, under coordinated vulnerability disclosure. Because the flaw stems from how the server validates incoming agent polling protocol interactions, a remote attacker can exploit it to bypass server authentication checks without valid user credentials or an existing session.

Exploiting this vulnerability enables an attacker to achieve remote code execution with the exact operating system privileges of the TeamCity server process. Depending on those process permissions, successful exploitation allows an adversary to exfiltrate TeamCity data, stored credentials, and configuration files, and to alter server state. Because CI/CD infrastructure orchestrates core deployment pipelines, compromising the server process also introduces significant risk to downstream build artifacts and the integrity of the software supply chain.

Evaluating risk requires understanding the distinction between software deployment models. The vulnerability strictly impacts TeamCity On-Premises, which refers to the customer-managed software edition administered by an organization on its local physical hardware, internal private clouds, or public cloud platform virtual machines. Conversely, JetBrains TeamCity Cloud refers to the fully managed software-as-a-service platform hosted by JetBrains, where JetBrains engineers have already applied the necessary mitigations across all environments and confirmed there is no evidence of active exploitation.

JetBrains has addressed CVE-2026-63077 by releasing updated software versions alongside a standalone security patch plugin for legacy installations. Organizations can resolve the issue by updating self-hosted servers to version 2025.11.7 or 2026.1.3. For customer-managed environments unable to perform a full server upgrade immediately, JetBrains released a security patch plugin compatible with TeamCity 2017.1 and newer, allowing organizations to fix the flaw without a full platform upgrade.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272