Act
active
CISA KEV: TeamCity CVE-2026-63077 RCE Actively Exploited
- Engineer — Act: Patch on-premise JetBrains TeamCity to the fixed version immediately — CISA KEV listing confirms active exploitation, a public PoC is on GitHub, and the unauthenticated deserialization flaw carries a 9.8 CVSS score. Also audit TeamCity for unauthorized admin accounts or altered build configurations.
- SOC/IR — Act: TeamCity servers are pre-authentication targets; assume-breach sweep is warranted — hunt for anomalous build jobs, new admin accounts, or outbound connections from CI/CD hosts since patch disclosure. Map exploitation behavior to ATT&CK T1190 (Exploit Public-Facing Application) and tune EDR/SIEM rules for post-exploitation on build agents.
- Leader — Act: On-premise TeamCity RCE under active exploitation carries supply-chain risk comparable to prior CI/CD incidents — confirm this quarter whether your organization runs on-premise TeamCity instances and verify patch status with engineering before end of week.
- Signals: CVE-2026-63077 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.