Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

CI/CD Tools Exploited: TeamCity Pre-Auth RCE CVE-2026-63077 (Ransomware) and JFrog Artifactory Admin Bypass CVE-2026-82329

Critical CVE-2026-63077, CVE-2026-82329, CVE-2026-42016, CVE-2026-42018, CVE-2026-66384 — JetBrains TeamCity has an unauthenticated RCE through the agent polling protocol, used by ransomware, and JFrog Artifactory has four exploited flaws including a default-config admin takeover. Fixed versions and how to protect your build pipeline.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Your build server and artifact repository hold the keys to everything you ship. TeamCity before 2026.1.3 / 2025.11.7 allows unauthenticated RCE (CVSS 9.8), and CISA lists ransomware use. Artifactory has a default-configuration auth bypass to admin (CVSS 9.8) plus three related flaws, all exploited. Upgrade both and rotate the secrets they hold.

CVE-2026-63077TeamCity: unauthenticated RCE via agent polling protocol. CVSS 9.8. Fixed 2026.1.3 / 2025.11.7. KEV 2026-08-05, known ransomware use
CVE-2026-82329Artifactory: unauthenticated → admin under default config. CVSS 9.8. KEV 2026-09-02
CVE-2026-42016Artifactory: token scope not checked → privilege escalation. CVSS 8.1. Fixed 7.133.11
CVE-2026-42018Artifactory: leaks internal anonymous-user token even with anonymous access off. CVSS 7.5
CVE-2026-66384Artifactory: authenticated write outside Docker cache path. CVSS 5.3
Artifactory fixed (all four)7.111.21 · 7.117.28 · 7.125.20 · 7.133.29 · 7.146.38 · 7.161.20, or later

Why build tools are a prime target

A CI server has credentials for your source code, cloud accounts, container registries and production deploys. An artifact repository decides which binaries and packages your developers and servers download. Owning either lets an attacker steal everything or plant a backdoor in what you ship. That’s why ransomware and supply-chain groups both go after them.

JetBrains TeamCity: CVE-2026-63077

TeamCity build agents check in with the server over an agent polling protocol. Before 2026.1.3 (and 2025.11.7 on the older line), that protocol could be abused by an unauthenticated attacker to execute code on the TeamCity server. CISA flags known ransomware use. TeamCity Cloud is managed by JetBrains; on-premises servers need updating.

JFrog Artifactory: four exploited bugs

  • CVE-2026-82329: under default configuration, an unauthenticated attacker with network access may obtain administrative privileges.
  • CVE-2026-42016: Artifactory validated a token’s signature and issuer but not its scope, so a low-privilege token could be used for more than it should.
  • CVE-2026-42018: Artifactory could hand an internal anonymous-user token to an unauthenticated caller even with anonymous access disabled.
  • CVE-2026-66384: an authenticated user could write outside the Docker remote-repository cache path under specific conditions.

JFrog Cloud (SaaS) is patched by JFrog. Self-hosted Artifactory needs updating.

Am I affected?

  • TeamCity: version is in the footer of every page and under Administration → Server Administration → Diagnostics. Vulnerable below 2026.1.3 (or below 2025.11.7 on 2025.11).
  • Artifactory: curl -s https://<artifactory>/artifactory/api/system/version or Administration → Monitoring → Service Status. Compare to the fixed builds in the box above for your release line.

How to patch

  • TeamCity: back up (Administration → Backup), then use the built-in upgrade or install the new version from jetbrains.com. Agents update themselves after the server upgrade.
  • Artifactory: follow JFrog’s upgrade guide for your install type (Docker, Helm, RPM/DEB). Upgrade to the latest patch on your line or to a newer line.

After patching: rotate secrets

  • Rotate credentials stored in TeamCity (VCS roots, cloud profiles, deploy keys, parameters marked as passwords) and Artifactory (admin passwords, access tokens, remote-repository credentials).
  • Revoke and reissue Artifactory access tokens; review the token list for any you don’t recognise.
  • Check TeamCity build configurations and Artifactory repositories for recent changes nobody made. A modified build step or an overwritten artifact is how supply-chain attacks hide.

Hardening

  • Keep CI and artifact servers off the internet. Developers can reach them over VPN; cloud agents can use private networking.
  • Disable anonymous access in Artifactory unless you deliberately run a public mirror.
  • Pin and verify artifact checksums/signatures in your deploy pipeline so a tampered artifact fails loudly.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories