JetBrains TeamCity servers are being attacked in the wild, and CISA has set a federal patch deadline. The agency placed CVE-2026-63077 on its Known Exploited Vulnerabilities catalog, requiring federal civilian agencies under Binding Operational Directive 26-04 to patch or mitigate by August 8, 2026.
The vulnerability is a deserialization of untrusted data with a CVSS score of 9.8. Reachable through the agent polling protocol, it lets an unauthenticated attacker slip past authentication and run arbitrary operating system commands with the privileges of the TeamCity server process. CISA’s catalog entry confirms active exploitation, though the threat actors, methods, and scale are unknown, and JetBrains has not confirmed the attacks in its own advisory.
The blast radius covers more than the box itself. Beyond leaking TeamCity data, configurations, and stored credentials, an exploit can change server state and compromise build artifacts plus the CI/CD pipelines that rely on them, which makes the bug a supply chain hazard for organizations that ship software built on TeamCity.
JetBrains patched the issue in late July and urged on-premise customers to upgrade immediately. CISA’s addition turns that recommendation into a hard deadline for federal agencies.
Defenders should apply vendor updates at once, review existing servers for indicators of compromise, and treat the agent polling protocol as a reachable attack surface. Given how deeply TeamCity sits in the software build process, a compromise can cascade into signed pipelines and downstream customers.
