CISA KEV Catalog Addition: JetBrains TeamCity Deserialization Vulnerability (CVE-2026-63077)
First seen Aug 6, 2026 · Updated Aug 6, 2026
CISA has added CVE-2026-63077, a deserialization of untrusted data vulnerability in JetBrains TeamCity, to its Known Exploited Vulnerabilities catalog based on confirmed active exploitation. Under BOD 26-04, FCEB agencies must prioritize remediation of this vulnerability on publicly exposed assets, as it may grant attackers total control of affected systems post-exploitation. All organizations, including those outside federal scope, are strongly encouraged to remediate promptly given the severity of CI/CD compromise.
Technical Analysis
CVE-2026-63077 is a deserialization of untrusted data vulnerability in JetBrains TeamCity, a widely used CI/CD server, allowing attackers to craft malicious serialized objects that execute arbitrary code when processed by vulnerable TeamCity instances. Exploitation of deserialization flaws in CI/CD platforms typically enables remote code execution, granting attackers the ability to pivot into build pipelines, exfiltrate secrets, or inject malicious code into software artifacts. Given TeamCity's role as a build/deployment orchestrator, successful exploitation could grant threat actors total control over the host and downstream supply chain assets. CISA's classification under BOD 26-04 as a vulnerability capable of granting total post-exploitation control underscores its critical operational risk. Organizations that run AI agent development pipelines, automated model training/deployment workflows, or agent-orchestrated CI/CD processes on TeamCity are at direct risk of credential theft, poisoned build artifacts, or supply-chain compromise of agent tooling and dependencies, making this a high-priority patch for any agent-enabled DevOps environment.
Affected Systems
JetBrains TeamCity server installations (on-premises), specifically versions vulnerable to CVE-2026-63077 deserialization flaw; publicly exposed TeamCity instances are at highest risk
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) provided in source material; organizations should monitor TeamCity server logs for anomalous deserialization requests, unexpected build job creation, and unauthorized plugin installations
Remediation Steps
- 1
Apply JetBrains Security Patch
Update all JetBrains TeamCity instances to the latest patched version addressing CVE-2026-63077 immediately.
- 2
Restrict Public Exposure
Remove TeamCity servers from direct internet exposure or place behind VPN/zero-trust access controls until patched.
- 3
Compromise Assessment
Per BOD 26-04 guidance, check whether the system was compromised prior to patching by reviewing logs, build history, and artifact integrity.
- 4
Rotate Credentials
Rotate all secrets, API keys, and service account credentials accessible from or stored within the TeamCity environment, including any keys used by AI agent or automation pipelines.
- 5
Audit CI/CD Pipeline Integrity
Verify integrity of recent build artifacts and deployment pipelines, especially those feeding AI agent, model, or automation infrastructure, to rule out supply-chain tampering.
- 6
Monitor KEV Catalog
Track CISA's KEV Catalog for related advisories and apply BOD 26-04 prioritization criteria for future high-risk vulnerabilities.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.