HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Remote Code Execution in JetBrains TeamCity On‑Premises (CVE‑2026‑63077) Added to CISA KEV Catalog

JetBrains TeamCity on‑premise servers contain a critical RCE flaw (CVE‑2026‑63077) that lets unauthenticated attackers execute OS commands. The vulnerability is now listed in CISA’s KEV catalog, prompting immediate patching and evidence capture for SOC 2 compliance.

LiveThreat™ Intelligence · 📅 August 06, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

Critical Remote Code Execution in JetBrains TeamCity On‑Premises (CVE‑2026‑63077) Added to CISA KEV Catalog

What It Is — A critical RCE flaw (CVE‑2026‑63077) in JetBrains TeamCity Server allows an unauthenticated attacker to bypass authentication via the agent‑polling protocol and execute arbitrary OS commands.

Exploitability — CVSS 9.8 (Critical). No public exploits observed yet, but the vulnerability is listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog, indicating high attacker interest.

Affected Products — JetBrains TeamCity On‑Premises (all versions prior to 2025.11.7 and 2026.1.3). Cloud‑hosted TeamCity instances are already patched.

Why It Matters for Compliance & Audit Readiness

  • Access‑control hygiene – SOC 2 CC6.1 requires logical access mechanisms to be enforced; an authentication bypass directly violates this control.
  • Patch‑management evidence – Continuous monitoring of remediation (upgrade or patch‑plugin) provides audit‑ready proof of due diligence.
  • Change‑management traceability – Documenting the remediation steps satisfies SOC 2 CC7.2 (change control) and demonstrates a defensible security posture to enterprise customers.

Recommended Actions

  • Upgrade all on‑prem TeamCity servers to 2025.11.7 or 2026.1.3 immediately.
  • If upgrade is delayed, apply the JetBrains security‑patch plugin (supports 2017.1+).
  • Restrict external HTTP(S) access – enforce VPN or IP‑allowlists and isolate CI servers from build agents.
  • Capture remediation evidence (patch logs, configuration changes) in a centralized control‑mapping repository for SOC 2 audit readiness.

Source: Security Affairs

📰 Original Source
https://securityaffairs.com/196725/security/u-s-cisa-adds-a-jetbrains-teamcity-flaw-to-its-known-exploited-vulnerabilities-catalog.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →