Critical RCE in JetBrains TeamCity (CVE‑2026‑63077) Under Active Exploitation
What It Is — JetBrains TeamCity on‑premise servers contain a deserialization flaw (CVE‑2026‑63077) that permits unauthenticated remote code execution. The vulnerability scores 9.8 (CVSS v3.1) and is being actively exploited in the wild, according to CISA.
Exploitability — Public exploits have been observed; a patch was released on 2026‑08‑02.
Affected Products — JetBrains TeamCity 2022.2 and earlier on‑premise installations (Windows, Linux).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Control CC6.1 (System Operations) requires continuous monitoring of privileged execution paths; an unpatched RCE defeats that monitoring.
- Evidence of timely patch management (CC7.1 – Change Management) is a core audit artifact; failure to apply the fix can be cited as a control deficiency.
- Enterprise buyers increasingly demand proof that CI/CD pipelines are hardened, making the vulnerability a red flag in vendor risk assessments.
Recommended Actions
- Apply JetBrains’ patch immediately and verify the version number.
- Update your SOC 2 control inventory: map the TeamCity service to CC6.1 and CC7.1, capture patch‑install logs as audit evidence.
- Enable runtime application self‑protection (RASP) or host‑based IDS to detect anomalous execution attempts.
- Conduct a post‑patch validation scan and document findings in your continuous compliance dashboard.
Source: The Hacker News – CISA Flags TeamCity CVE‑2026‑63077 RCE Flaw Under Active Exploitation