highZero-Day

CISA KEV Catalog Addition: JetBrains TeamCity Deserialization Vulnerability (CVE-2026-63077)

First seen Aug 6, 2026 · Updated Aug 6, 2026

CISAKEVJetBrainsTeamCitydeserializationCI/CDagent-relevantactive-exploitationfederal-mandate

CISA has added CVE-2026-63077, a deserialization of untrusted data vulnerability in JetBrains TeamCity, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Under BOD 26-04, FCEB agencies must prioritize remediation of this vulnerability on publicly exposed assets, as it may grant attackers total control of affected systems post-exploitation. All organizations, including those outside federal scope, are strongly encouraged to remediate promptly given the severity of CI/CD compromise.

Technical Analysis

CVE-2026-63077 is a deserialization of untrusted data vulnerability in JetBrains TeamCity, a widely used CI/CD server, allowing attackers to craft malicious serialized objects that execute arbitrary code when processed by vulnerable TeamCity instances. Exploitation of deserialization flaws in CI/CD platforms typically enables remote code execution, granting attackers the ability to pivot into build pipelines, exfiltrate secrets, or inject malicious code into software artifacts. Given TeamCity's role as a build/deployment orchestrator, successful exploitation could grant threat actors total control over the host and downstream supply chain assets. CISA's classification under BOD 26-04 as a vulnerability capable of granting total post-exploitation control underscores its critical operational risk. Organizations that run AI agent development pipelines, automated model training/deployment workflows, or agent-orchestrated CI/CD processes on TeamCity are at direct risk of credential theft, poisoned build artifacts, or supply-chain compromise of agent tooling and dependencies, making this a high-priority patch for any agent-enabled DevOps environment.

Affected Systems

JetBrains TeamCity server installations (on-premises), specifically versions vulnerable to CVE-2026-63077 deserialization flaw; publicly exposed TeamCity instances are at highest risk

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) provided in source material; organizations should monitor TeamCity server logs for anomalous deserialization requests, unexpected build job creation, and unauthorized plugin installations

Remediation Steps

  1. 1

    Apply JetBrains Security Patch

    Update all JetBrains TeamCity instances to the latest patched version addressing CVE-2026-63077 immediately.

  2. 2

    Restrict Public Exposure

    Remove TeamCity servers from direct internet exposure or place behind VPN/zero-trust access controls until patched.

  3. 3

    Compromise Assessment

    Per BOD 26-04 guidance, check whether the system was compromised prior to patching by reviewing logs, build history, and artifact integrity.

  4. 4

    Rotate Credentials

    Rotate all secrets, API keys, and service account credentials accessible from or stored within the TeamCity environment, including any keys used by AI agent or automation pipelines.

  5. 5

    Audit CI/CD Pipeline Integrity

    Verify integrity of recent build artifacts and deployment pipelines, especially those feeding AI agent, model, or automation infrastructure, to rule out supply-chain tampering.

  6. 6

    Monitor KEV Catalog

    Track CISA's KEV Catalog for related advisories and apply BOD 26-04 prioritization criteria for future high-risk vulnerabilities.

CVE / Advisory IDs

CVE-2026-63077

Industries Most Exposed

software developmenttechnologyfederal governmentDevOps/CI-CD service providersany organization using TeamCity for build automation

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.