A maximum severity unauthenticated remote code execution vulnerability residing inside an enterprise continuous integration build platform has been added to the federal directory of confirmed active internet threats. The defect enables unauthenticated network actors to bypass login authorization checks and execute arbitrary system commands on underlying build servers.
Tracked as CVE-2026-63077 with a CVSS score of 9.8, the vulnerability impacts all TeamCity On-Premises release builds prior to versions 2025.11.7 and 2026.1.3. The security defect stems from an untrusted data deserialization flaw in the agent polling protocol handler. An attacker can craft specialized HTTP or HTTPS requests to bypass authentication controllers, deserializing malicious objects that execute background shell commands under the context of the TeamCity process user. Due to active wild target probes, CISA has added the vulnerability to the Known Exploited Vulnerabilities catalog under Binding Operational Directive 26-04 mandates.
Subverting build automation infrastructure introduces extreme software supply chain risk across the enterprise. Because CI/CD platforms hold code signing keys, cloud deployment credentials, and internal repository access tokens, an administrative takeover allows attackers to inject malicious code into production software builds, steal intellectual property, and pivot into corporate cloud environments.
– Upgrade TeamCity On-Premises installations to patched versions 2025.11.7 or 2026.1.3 immediately, or apply the official security patch plugin for legacy versions.
– Restrict web access to TeamCity management interfaces by placing build servers behind authenticated zero trust access gateways.
– Inspect build agent execution logs and audit records for anomalous API queries or unverified administrative user account additions.
– Rotate all production deployment credentials, repository tokens, and code signing certificates stored within build environment variables.
Continuous integration build server protection demands immediate patch deployment combined with strict network interface controls to ensure automated development infrastructure remains shielded from unauthenticated exploitation. #CodeDefence #JetBrains #TeamCity #RCE #Deserialization #DevSecOps #SupplyChain #CISA #KEV
/
