Knox CVE Database
/
CVE-2026-63077
Critical
9.8

CVE-2026-63077: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.

Added to the CISA KEV catalog:
August 5, 2026

Overview

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Vulnerability details

Affected vendor
JetBrains
Affected product
TeamCity
Weakness type (CWE)
CWE-502

JetBrains TeamCity exposes an agent polling protocol endpoint that build agents use to retrieve work from the server. This endpoint deserializes incoming data without first authenticating the connecting party, a classic CWE-502 failure. In deserialization vulnerabilities, the application reconstructs objects from attacker-supplied bytes before any validation logic can act on the result. Because object construction itself executes code in many serialization frameworks, a crafted payload can trigger arbitrary method calls during the deserialization step, before the application has any opportunity to inspect or reject the content.

An attacker who can reach the TeamCity agent polling protocol port over the network sends a crafted serialized payload to that endpoint. No credentials, session token, or prior access are required. The TeamCity server process deserializes the payload, executing attacker-controlled code in the context of the server. Successful exploitation yields full remote code execution on the TeamCity server, giving the attacker read and write access to build configurations, source code, secrets, and pipeline artifacts, as well as the ability to disrupt availability entirely. The sole precondition is network reachability of the agent polling port.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor TeamCity server process logs for unexpected child process creation or outbound connections initiated by the server process itself, which would indicate post-exploitation activity following deserialization.
  • Audit network access logs for connections to the TeamCity agent polling port originating from IP addresses outside the defined build agent pool. Legitimate agent traffic comes from a bounded, known set of hosts; any connection from an unrecognized source warrants investigation.
  • Review TeamCity internal audit logs for new administrator account creation, build configuration changes, or token generation events that do not correspond to an authenticated user session, which may indicate post-exploitation persistence.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 8, 2026

Additional hardening

  • Restrict network access to the TeamCity agent polling port using firewall rules or host-based controls so only known build agent IP addresses can reach it.
  • Place the TeamCity server behind a network segment that is not directly reachable from untrusted networks; require agents to connect through a controlled network path.
  • Enumerate all internet-facing TeamCity instances and remove direct public exposure of any TeamCity port until the patched version is deployed.
  • Audit the TeamCity server host for new scheduled tasks, cron jobs, or added user accounts as forensic triage steps, consistent with CISA forensics triage requirements for this vulnerability.

Key dates

Published (NVD)
July 27, 2026
Added to CISA KEV
August 5, 2026
Remediation deadline
August 8, 2026
Last updated
August 6, 2026

References

Frequently asked questions

Does CVE-2026-63077 affect my FedRAMP authorization?

If JetBrains TeamCity runs inside your authorization boundary, yes. CVE-2026-63077 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, which carries a remediation deadline of August 8, 2026. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding — one you either remediate or formally document a mitigation for before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-63077?

Knox doesn't patch your software for you — remediating JetBrains TeamCity is your responsibility under the FedRAMP shared responsibility model. What Knox gives you is the pre-authorized, single-tenant boundary to remediate in, plus continuous compliance monitoring and audit-artifact coverage that help you document the fix for your next assessment. The fix is yours to apply; staying compliant while you apply it isn't something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's continuous monitoring, powered by KnoxAI, watches your environment in real time for newly disclosed vulnerabilities and compliance issues. Exposure surfaces as part of ongoing monitoring — not only when an assessor flags it at review time.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path — FedRAMP in 90 days for 90% less, without dependency or delay.

What happens if CVE-2026-63077 isn't remediated by August 8, 2026?

It becomes a POA&M item, and a growing POA&M list is what turns a routine continuous-monitoring review into a real conversation with your agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

What this vulnerability means for your FedRAMP compliance

Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, FedRAMP continuous monitoring puts a hard remediation clock on it. The clock starts on awareness — and missing the deadline can put an Authority to Operate at risk.

FedRAMP remediation deadlines for actively exploited vulnerabilities

FedRAMP ConMon SLAs give cloud providers 30, 90, or 180 days by severity — but KEV-listed flaws carry the tighter CISA deadline shown above. For authorized services, that date is the compliance line that assessors and agency sponsors will check.

How Knox reduces the burden of CVE vulnerabilities

Remediating the flaw is your responsibility under the FedRAMP shared responsibility model — but staying compliant while you fix it isn't something you manage alone. KnoxAI's continuous monitoring surfaces exposure in real time, and Knox keeps your continuous-monitoring evidence and audit artifacts current while you apply the fix. Learn more about the Knox platform.

How to limit your exposure through inherited controls and isolation

Knox's single-tenant architecture gives every customer a dedicated boundary, and 60–80% of FedRAMP controls are inherited from the platform — shrinking the surface you have to patch and prove. See why teams choose Knox.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting