🔴 Critical | Source: CISA Known Exploited Vulnerabilities
A critical vulnerability in JetBrains TeamCity allows unauthenticated attackers to execute arbitrary code remotely by exploiting unsafe deserialisation in the agent polling protocol. Because TeamCity is widely used as a CI/CD platform, a successful attack could give an adversary full control over build pipelines, enabling supply-chain compromise or lateral movement into cloud environments. CISA has confirmed active exploitation and mandates remediation by 8 August 2026.
Security Architect’s Take: Patch affected TeamCity instances immediately and, if patching cannot be completed at once, restrict network access to the agent polling port to trusted build agents only — ideally via security group or firewall rules. Audit recent build logs and pipeline configurations for signs of tampering or unexpected artefact modifications.
Original advisory: CVE-2026-63077: JetBrains TeamCity