The Build Server Is the Prize: TeamCity CVE-2026-63077 Goes From KEV to Ransomware as JetBrains Ships 40 More Fixes

On 5 October 2026, JetBrains shipped bug-fix updates TeamCity 2026.2.1 and 2026.1.5, addressing over 40 vulnerabilities combined across the two release trains and urging customers to upgrade as soon as possible. The announcement doubles as a follow-up to the 27 July disclosure of CVE-2026-63077: since that announcement, JetBrains says, it has received reports of active exploitation, as well as attempted exploitation, targeting unpatched TeamCity servers, and it has published additional guidance for the flaw. The vulnerability is a CVSS 9.8 unauthenticated remote code execution via the agent polling protocol — deserialization of untrusted data (CWE-502) in TeamCity before 2026.1.3 and 2025.11.7 — and CISA has now flagged it as Known ransomware-campaign use.

The paper trail is unusually complete and worth reading in order. NVD published the record on 27 July. CISA added it to the Known Exploited Vulnerabilities catalog on 5 August with a three-day federal deadline of 8 August — the short fuse reserved for flaws already burning. On 23 September, CISA warned that ransomware groups were actively exploiting it. On 5 October, JetBrains confirmed the exploitation reports itself and shipped 40 more fixes on top. Each step narrowed the same conclusion: the unpatched build server is not a hypothetical.

Why the agent polling protocol is the wrong place for this bug

The vulnerable surface is the protocol build agents use to poll the server — infrastructure that is routinely reachable from broad network segments because agents live everywhere builds run. An unauthenticated deserialization flaw there means the attacker’s entry point is the port the architecture requires you to expose, not an edge case somebody misconfigured. The CVSS vector says it plainly: network, low complexity, no privileges, no interaction, full confidentiality-integrity-availability impact.

And the asset behind that port is close to the crown jewels. TeamCity holds source checkouts, build secrets, cloud credentials, signing material, and deploy tokens — everything a software supply-chain attacker needs to turn one compromised server into trojaned artifacts shipped to every downstream consumer. The 2024 TeamCity auth-bypass wave already demonstrated the playbook; a 9.8 with a Known ransomware flag is the same target with a louder timer. This is the same arithmetic behind the KEV entries we have tracked all month — NetScaler’s same-day KEV addition, FortiMail’s zero-day KEV listing — except here the KEV entry is two months old and the exploitation is confirmed by the vendor, not merely catalogued.

Forty fixes is the second story

Buried in the upgrade notice is the larger signal: two routine bug-fix releases carrying over 40 security fixes between them. JetBrains’ framing — “similarly to the previous updates, these focus heavily on security issues” — suggests this volume is the new normal for the product, not an exception. Administrators who treated 2026.1.3 / 2025.11.7 as the end of the July incident should recalibrate: the October trains contain dozens more flaws, at least one additional account-takeover class reported in the same window, and the vendor’s own recommendation is immediate upgrade across both supported lines.

The compatibility note softens the operational cost deliberately: bug-fix updates within the same major share data format, so upgrades and downgrades inside the series need no backup-and-restore cycle. That sentence is aimed squarely at the teams still deferring the July patch — the friction excuse is gone, and the exploitation evidence is in.

What to do

  • Upgrade to 2026.2.1 or 2026.1.5 immediately. The July fix (2026.1.3 / 2025.11.7) stops CVE-2026-63077, but the October trains close 40 more holes. Do not stop at the July version.
  • Assume unpatched servers are compromised, not merely vulnerable. KEV-listed since August, ransomware-flagged since September, vendor-confirmed active exploitation in October. Hunt for intruders — unexpected agents, new admin accounts, modified build configurations, outbound connections — before trusting the host.
  • Rotate everything the server touched. Cloud credentials, deploy tokens, signing keys, VCS credentials. A build-server compromise outlives the patch if stolen secrets stay valid.
  • Segment the agent polling port. The vulnerable protocol is reachable by design wherever agents run. Restrict which networks can reach the TeamCity server port, and treat agent fleets as untrusted input to the server, not the reverse.
  • Audit build artifacts produced during the exposure window. If the server was unpatched at any point since late July, artifacts it produced should be treated as potentially tainted until proven otherwise — verify provenance before they ship further downstream.

Verification note: the CVSS 9.8 score, vector, CWE-502 classification, agent-polling-protocol description, affected versions and 27 July publication date come from the NVD CVE 2.0 API record for CVE-2026-63077, checked 6 October 2026. The KEV date-added (5 August 2026), 8 August federal deadline, and Known ransomware-campaign-use flag come from the CISA KEV catalog CSV pulled the same day. The 5 October releases, the “over 40 vulnerabilities combined” count, the upgrade recommendation, and the active-exploitation confirmation come from JetBrains’ TeamCity blog post of 5 October 2026, which links the vendor’s follow-up CVE-2026-63077 guidance. The 23 September CISA ransomware warning is via contemporaneous secondary reporting. We tested nothing, exploited nothing, and did not contact JetBrains before publication.

Sources: