Return to Threats

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

thehackernews.com 2026-08-06 AI supply chain Critical

What Happened

A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a case of deserialization of untrusted data that could allow an unauthenticated attacker with access to a TeamCity server

Why It Matters

According to CISA and multiple vulnerability advisories, CVE-2026-63077 is a critical unauthenticated remote code execution flaw in on-premise JetBrains TeamCity, caused by deserialization of untrusted data in the agent polling protocol, and is now under active exploitation in the wild.[1][2][3][4][5] This affects all self-hosted TeamCity versions prior to 2025.11.7 and 2026.1.3 and allows network attackers to execute arbitrary OS commands with the privileges of the TeamCity server process, potentially compromising CI/CD pipelines and downstream artifacts.[1][2][3] From a RealGround perspective, compromised TeamCity instances in the software supply chain can be used to inject malicious code or configuration into AI systems and agents built or deployed via these pipelines, creating a high-risk path for indirect compromise of AI models, services, and SBOM integrity. Organizations should rapidly patch or apply the security plugin, restrict network access to CI/CD infrastructure, and incorporate this vulnerability into AI supply chain and SBOM risk assessments to ensure AI components built through TeamCity are trustworthy and have not been tampered with.[1][3]

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/08/cisa-flags-teamcity-cve-2026-63077-rce.html

Talk to AI CISO