Critical CVE-2026-63077, CVE-2026-82329, CVE-2026-42016, CVE-2026-42018, CVE-2026-66384 — JetBrains TeamCity has an unauthenticated RCE through the agent polling protocol, used by ransomware, and JFrog Artifactory has four exploited flaws including a default-config admin takeover. Fixed versions and how to protect your build pipeline.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Your build server and artifact repository hold the keys to everything you ship. TeamCity before 2026.1.3 / 2025.11.7 allows unauthenticated RCE (CVSS 9.8), and CISA lists ransomware use. Artifactory has a default-configuration auth bypass to admin (CVSS 9.8) plus three related flaws, all exploited. Upgrade both and rotate the secrets they hold.
| CVE-2026-63077 | TeamCity: unauthenticated RCE via agent polling protocol. CVSS 9.8. Fixed 2026.1.3 / 2025.11.7. KEV 2026-08-05, known ransomware use |
|---|---|
| CVE-2026-82329 | Artifactory: unauthenticated → admin under default config. CVSS 9.8. KEV 2026-09-02 |
| CVE-2026-42016 | Artifactory: token scope not checked → privilege escalation. CVSS 8.1. Fixed 7.133.11 |
| CVE-2026-42018 | Artifactory: leaks internal anonymous-user token even with anonymous access off. CVSS 7.5 |
| CVE-2026-66384 | Artifactory: authenticated write outside Docker cache path. CVSS 5.3 |
| Artifactory fixed (all four) | 7.111.21 · 7.117.28 · 7.125.20 · 7.133.29 · 7.146.38 · 7.161.20, or later |
A CI server has credentials for your source code, cloud accounts, container registries and production deploys. An artifact repository decides which binaries and packages your developers and servers download. Owning either lets an attacker steal everything or plant a backdoor in what you ship. That’s why ransomware and supply-chain groups both go after them.
TeamCity build agents check in with the server over an agent polling protocol. Before 2026.1.3 (and 2025.11.7 on the older line), that protocol could be abused by an unauthenticated attacker to execute code on the TeamCity server. CISA flags known ransomware use. TeamCity Cloud is managed by JetBrains; on-premises servers need updating.
JFrog Cloud (SaaS) is patched by JFrog. Self-hosted Artifactory needs updating.
curl -s https://<artifactory>/artifactory/api/system/version or Administration → Monitoring → Service Status. Compare to the fixed builds in the box above for your release line.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.