preloader

· · devops digital-security cve ci-cd jetbrains cisa-kev vulnerability-management patch-management europe supply-chain

CISA Gave Organisations Three Days to Patch This CI/CD Server Flaw. The Deadline Is Today

Source: SecurityWeek

CI/CD servers hold everything an attacker needs to compromise a company’s entire software supply chain in one place: deployment credentials, signing keys, pipeline configuration, and access to every repository the build system touches. That is exactly the target CVE-2026-63077 hands over, and it does so to an attacker who has not logged in.

No login required

CVE-2026-63077 carries a CVSS score of 9.8. The root cause is a deserialization flaw, CWE-502, sitting inside the protocol TeamCity build agents use to poll the server for work. An unauthenticated attacker with plain HTTP or HTTPS access to a TeamCity On-Premises server can send a crafted request through that protocol, bypass authentication entirely, and execute arbitrary operating system commands with the same privileges as the TeamCity server process itself. JetBrains disclosed it on 27 July and shipped fixes in versions 2025.11.7 and 2026.1.3; a security patch plugin is available for anyone on 2017.1 or later who cannot upgrade immediately. TeamCity Cloud is not affected.

Why CISA’s three-day window is unusual

CISA added the flaw to its Known Exploited Vulnerabilities catalog on 5 August after confirming active exploitation, and set the remediation deadline for 8 August, today. Most KEV deadlines run two to three weeks; a three-day window signals CISA saw exploitation moving fast enough that the normal timeline would leave federal systems exposed. The KEV catalog is written for US federal agencies, but every serious security team treats it as a proxy for what is actively being weaponised right now, and this one is.

What a compromised build server actually costs you

TeamCity is JetBrains’ CI/CD platform, and it is deeply embedded in European engineering organisations, JetBrains itself is headquartered in Prague with deep roots across the Czech Republic and wider EU developer community. A successful exploit here does not just give an attacker a foothold; it gives them the same trust every downstream deployment already extends to the build server. Stored credentials, signing keys, and the ability to insert malicious code into build artefacts before they ever reach production are all in scope. For any organisation subject to NIS2’s incident reporting obligations, an exploited build server that touched customer-facing code is not a hypothetical scenario worth a tabletop exercise, it is the kind of significant incident the directive requires you to be able to detect and report within 24 hours.

If your organisation runs TeamCity On-Premises and you are not certain every instance is patched to 2025.11.7 or 2026.1.3, or you need help auditing what a compromised build server could have touched, contact Excello Digital. We help European engineering teams secure their CI/CD infrastructure and build the incident response processes NIS2 now requires.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!