Critical Remote Code Execution in JetBrains TeamCity On‑Premises (CVE‑2026‑63077) Added to CISA KEV Catalog
What It Is — A critical RCE flaw (CVE‑2026‑63077) in JetBrains TeamCity Server allows an unauthenticated attacker to bypass authentication via the agent‑polling protocol and execute arbitrary OS commands.
Exploitability — CVSS 9.8 (Critical). No public exploits observed yet, but the vulnerability is listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog, indicating high attacker interest.
Affected Products — JetBrains TeamCity On‑Premises (all versions prior to 2025.11.7 and 2026.1.3). Cloud‑hosted TeamCity instances are already patched.
Why It Matters for Compliance & Audit Readiness
- Access‑control hygiene – SOC 2 CC6.1 requires logical access mechanisms to be enforced; an authentication bypass directly violates this control.
- Patch‑management evidence – Continuous monitoring of remediation (upgrade or patch‑plugin) provides audit‑ready proof of due diligence.
- Change‑management traceability – Documenting the remediation steps satisfies SOC 2 CC7.2 (change control) and demonstrates a defensible security posture to enterprise customers.
Recommended Actions
- Upgrade all on‑prem TeamCity servers to 2025.11.7 or 2026.1.3 immediately.
- If upgrade is delayed, apply the JetBrains security‑patch plugin (supports 2017.1+).
- Restrict external HTTP(S) access – enforce VPN or IP‑allowlists and isolate CI servers from build agents.
- Capture remediation evidence (patch logs, configuration changes) in a centralized control‑mapping repository for SOC 2 audit readiness.
Source: Security Affairs