Progress LoadMaster and JetBrains TeamCity Flaws Under Active Attack: CISA Emergency Patching Required

Have you ever locked the front door but left a side entrance wide open?

You may have strong passwords, antivirus, backups, and employee security training in place. But if an internet-facing network appliance or development server is running vulnerable software, attackers may still have a direct path into your business.

That is the concern behind two recent additions to CISA’s Known Exploited Vulnerabilities Catalog: CVE-2026-8037 in Progress LoadMaster and CVE-2026-63077 in JetBrains TeamCity On-Premises.

Both vulnerabilities can allow unauthenticated attackers to execute operating system commands remotely. Both have confirmed active exploitation. And both were assigned extremely short remediation deadlines under CISA’s new Binding Operational Directive 26-04.

The deadlines have already passed as of August 11, 2026. If you still operate either product, treat this as an emergency remediation and investigation matter, not a routine maintenance task.

The two vulnerabilities at a glance

Product Vulnerability Risk CISA date added CISA due date
Progress LoadMaster and related ADC products CVE-2026-8037 Unauthenticated command injection and remote code execution August 7, 2026 August 10, 2026
JetBrains TeamCity On-Premises CVE-2026-63077 Unauthenticated remote code execution through deserialization August 5, 2026 August 8, 2026

A CVE, or Common Vulnerabilities and Exposures identifier, is simply a tracking number for a known security flaw. The important detail here is not just the CVE score.

CISA’s KEV catalog means the vulnerability has reliable evidence of exploitation in the wild.

That changes the conversation.

CVE-2026-8037: Progress LoadMaster command injection

Progress LoadMaster is an application delivery controller, commonly used to balance traffic, manage connections, and help applications remain available.

Think of it as a traffic director standing in front of your business applications. It decides where incoming visitors go.

Now imagine that traffic director accepts a malicious instruction and passes it directly to the operating system. That is the basic business risk created by CVE-2026-8037.

The flaw is an OS command injection vulnerability in API and command endpoints. An unauthenticated attacker may send specially crafted input and execute arbitrary commands on the LoadMaster appliance.

No valid login may be required.

The vulnerability is rated critical, with CVSS scores of 9.6 and 9.8 reported by Progress and NIST. In plain language, successful exploitation could allow an attacker to take control of the appliance, alter its configuration, access sensitive information, disrupt application traffic, or use the device as a launching point into connected systems.

The affected products include:

  • Progress Kemp LoadMaster
  • Progress ECS Connection Manager
  • Progress Connection Manager for ObjectScale
  • Progress MOVEit WAF

According to the Progress security bulletin, affected LoadMaster versions include:

  • GA version 7.2.63.1 and earlier
  • LTSF version 7.2.54.17 and earlier

The fixed versions are:

  • LoadMaster GA 7.2.63.2
  • LoadMaster LTSF 7.2.54.18

Progress also provides fixed 7.2.63.2 releases for the affected Connection Manager products. Verify the exact version and upgrade path for your deployment before making changes.

Security engineer applying a firmware update to a network appliance

What to do if you operate LoadMaster

Start by identifying every affected appliance. Do not check only the equipment your central IT team remembers purchasing.

Look in:

  • On-premises server rooms
  • Cloud and virtual appliance inventories
  • Disaster recovery environments
  • Branch offices
  • Managed service provider accounts
  • Internet-facing IP address scans

Then take these actions:

  • Upgrade to the appropriate fixed Progress release immediately.
  • Remove management interfaces from the public internet.
  • Restrict WUI and API access to trusted administrator networks or jump hosts.
  • Review firewall rules, access control lists, and management VLAN settings.
  • Preserve relevant logs before making changes when possible.
  • Review configuration changes, administrator accounts, API keys, and outbound connections.
  • Rotate credentials and certificates if compromise is suspected.

Here’s the important point: patching closes the known hole, but it does not prove that nobody entered through it.

Because CISA has listed CVE-2026-8037 as actively exploited, investigate any LoadMaster appliance that was vulnerable and reachable from an untrusted network.

CVE-2026-63077: JetBrains TeamCity deserialization flaw

TeamCity is a continuous integration and continuous delivery platform. Development teams use it to build, test, package, and deploy software.

That makes a TeamCity server more than another application server. It may have access to source code, build scripts, artifact repositories, cloud credentials, deployment keys, and production environments.

Here’s the problem:

CVE-2026-63077 allows an unauthenticated attacker with HTTP or HTTPS access to a vulnerable TeamCity server to execute operating system commands through the agent polling protocol.

The flaw involves unsafe deserialization, which means the server processes specially crafted data in a way that can cause unintended commands to run.

You do not need to understand the underlying serialization technology to understand the risk. If an attacker reaches the vulnerable server, they may be able to operate it with the privileges assigned to the TeamCity service.

Depending on those privileges, the attacker could:

  • Read TeamCity configurations and stored credentials
  • Modify build processes
  • Insert malicious code into software builds
  • Access source code and artifacts
  • Move from the build server into connected systems
  • Tamper with downstream deployments

NIST lists the vulnerability as critical, with a CVSS score of 9.8.

JetBrains fixed the issue in:

  • TeamCity 2025.11.7
  • TeamCity 2026.1.3

All earlier TeamCity On-Premises versions should be considered vulnerable. TeamCity Cloud customers do not need to take action because JetBrains has already applied the necessary protections to that service.

Software development manager and IT consultant reviewing a secure CI/CD environment

What to do if you operate TeamCity On-Premises

Upgrade every TeamCity On-Premises server to a fixed release immediately. If a full upgrade cannot happen right away, JetBrains provides a security patch plugin for TeamCity 2017.1 and later.

For TeamCity 2024.03 and newer, administrators can review available security updates under Administration → Updates.

The plugin is an emergency measure. It addresses this specific vulnerability, but it does not replace a full version upgrade.

You should also:

  • Restrict TeamCity access to trusted networks and build agents.
  • Remove unnecessary internet exposure.
  • Require VPN access for administrative connections where appropriate.
  • Run the TeamCity service with the minimum operating system privileges required.
  • Keep TeamCity servers separate from build agents.
  • Rotate source control, artifact repository, cloud, and deployment credentials if exposure is possible.
  • Review build configurations and artifacts created since late July 2026.

JetBrains’ August 7 follow-up advisory reports active and attempted exploitation against unpatched servers.

It also provides useful investigation clues. Review TeamCity logs for:

  • com.thoughtworks.xstream.converters.ConversionException
  • com.thoughtworks.xstream.security.ForbiddenClassException

The first may indicate an attempted or successful exploit. The second may indicate that a patched server blocked an exploitation attempt.

Also review unauthorized build agents, especially unexpected agents with names beginning with scan.

One indicator alone does not prove compromise. But it deserves investigation.

What BOD 26-04 means for your business

CISA’s BOD 26-04 is legally binding for Federal Civilian Executive Branch agencies. It does not automatically impose federal obligations on every small business.

But it is an important risk-management benchmark for every organization.

BOD 26-04 considers four factors:

  1. Is the asset publicly exposed?
  2. Is the CVE listed in CISA’s KEV catalog?
  3. Can an attacker automate exploitation?
  4. Does exploitation provide partial or total control?

For these two vulnerabilities, the answers are serious. Both are KEV-listed, both can lead to total control, and both affect infrastructure that may sit at critical points in your environment.

CISA assigned:

  • August 8, 2026 as the TeamCity deadline
  • August 10, 2026 as the LoadMaster deadline

The dates are federal remediation deadlines, but the underlying message applies broadly: known exploited vulnerabilities should move to the front of your patch queue immediately.

And when a vulnerability may provide total control, CISA’s guidance also calls for forensic triage.

Your emergency response checklist

If either product exists in your environment, take these steps today:

  • Identify all affected systems and versions.
  • Determine whether each system is internet-facing.
  • Apply the vendor fix or approved security mitigation.
  • Restrict network access while remediation is underway.
  • Preserve logs and relevant evidence before making major changes when practical.
  • Search for suspicious commands, accounts, processes, configuration changes, or build activity.
  • Rotate credentials and secrets that may have been accessible.
  • Reissue certificates if private keys may have been exposed.
  • Review connected systems for lateral movement.
  • Document the timeline, actions taken, and evidence reviewed.
  • Escalate to incident response professionals if compromise is suspected.

Do not assume an asset is safe because it is “behind a firewall.” If an unauthenticated or untrusted party can reach it through the internet, a cloud network, a partner connection, or an overly broad internal rule, treat it as exposed.

The bigger lesson for small businesses

Most small businesses do not have unlimited staff or time. You cannot investigate every security alert with the same urgency.

That is exactly why CISA’s KEV catalog matters.

It helps you separate ordinary maintenance from vulnerabilities attackers are already using. A critical device or development server may be quietly supporting your operations today, but it can become the most dangerous doorway in your environment tomorrow.

Platinum Web Services helps businesses identify exposed systems, prioritize urgent patches, strengthen network controls, and investigate signs of compromise. You can also review our related guidance on patching CISA vulnerabilities for small businesses and active cyber threat alerts.

A patch is not just an update. It is one more lock on the door protecting your business.

And when attackers are already testing the handle, it is time to use it.

Category: CISA Advisories

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *