5 Ways You Can Use Deception in a Mythos-like AI Era

CVE-2026-63077

CVE-2026-63077: How a TeamCity Deserialization Flaw Opens the Door to RCE

CVSS Gauge
CVSS Needle

Summary

CVE-2026-63077 is a critical deserialization of untrusted data vulnerability in JetBrains TeamCity On-Premises. An unauthenticated attacker with HTTP(S) access to a vulnerable TeamCity server can abuse the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.

Successful exploitation can expose TeamCity data, configurations, and stored credentials. It can also allow changes to server state and potentially compromise build artifacts and downstream CI/CD pipelines. The vulnerability affects TeamCity versions before 2025.11.7 and 2026.1.3. CISA added the vulnerability to its KEV catalog on August 5, 2026, after exploitation was observed in the wild.

Urgent Actions Required

Which Systems Are Vulnerable to CVE-2026-63077?

Technical Overview 

How Does the CVE-2026-63077 Exploit Work?

The attack typically follows these steps:

CVE-2026-63077

What Causes CVE-2026-63077?

Vulnerability Root Cause:   

CVE-2026-63077 is caused by unsafe deserialization of untrusted data in TeamCity’s agent polling protocol. TeamCity’s XStream configuration allowed TeamCity classes without first clearing its default permissions. This left the deserialization process overly permissive, allowing attacker-controlled data to bypass authentication checks and trigger arbitrary operating system command execution.

How Can You Mitigate CVE-2026-63077?

If immediate patching is delayed or not possible: 

  • Install JetBrains’ security patch plugin for TeamCity 2017.1 and later.
  • Restrict network access to the TeamCity server and limit access to trusted users and systems.
  • Place internet-facing TeamCity servers behind a VPN or additional protective access layer.
  • Review TeamCity and relevant system logs for suspicious activity, especially if the server was exposed while unpatched.
  • If compromise is suspected, rotate credentials stored in TeamCity, including affected access tokens and keys.

Which Assets and Systems Are at Risk?

Will Patching CVE-2026-63077 Cause Downtime?

Patch application impact: Low. Upgrade to TeamCity 2025.11.7 or 2026.1.3. If upgrading is delayed, use JetBrains’ security patch plugin.

How Can You Detect CVE-2026-63077 Exploitation?

Exploitation Signatures:

Look for unusual HTTP(S) requests targeting the TeamCity agent polling protocol, especially from unknown sources. 

Indicators of Compromise (IOCs/IOAs): 

Behavioral Indicators:

Alerting Strategy:

Remediation & Response

See How Fidelis NDR Delivers Full-Spectrum Network Security

      • Gain deep visibility across ports and protocols
      • Detect threats with network traffic and behavior analysis
      • Correlate alerts to speed up investigation and response
      • Strengthen protection with DLP, sandboxing, and threat intelligence
      • Explore integrated deception and automated threat hunting
Download the Data Sheet

CVSS Breakdown Table 

MetricValue Description
Base Score9.8Critical vulnerability with high impact and remote exploitability
Attack VectorNetworkExploitable remotely through HTTP/HTTPS access
Attack ComplexityLowExploitation does not require special conditions
Privileges RequiredNoneNo authentication or prior privileges are required
User Interaction NoneExploitation requires no user action
Scope Unchanged The impact remains within the vulnerable TeamCity component
Confidentiality Impact HighSuccessful exploitation can expose TeamCity data, configurations, and stored credentials
Integrity Impact HighAttackers can execute commands and potentially modify server state and CI/CD artifacts
Availability ImpactNoneArbitrary OS command execution can affect the availability of the TeamCity server

Related Readings

One Platform for All Adversaries

See Fidelis in action. Learn how our fast and scalable platforms provide full visibility, deep insights, and rapid response to help security teams across the World protect, detect, respond, and neutralize advanced cyber adversaries.