CVE-2026-63077
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: in JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent…
CISA federal remediation date Aug 8
Vulnerabilities · 52 days ago
CISA’s KEV listing moves TeamCity from a patchable server bug to proof that the build control plane is already being hit. The weak point is the agent polling trust path, where an unauthenticated request can ride in as trusted data and reach the TeamCity server process, so patching the host alone does not capture the blast radius.
CVE-2026-63077 is a deserialization of untrusted data flaw in TeamCity On-Premises. JetBrains fixed it in 2026.1.3 and 2025.11.7, and released a security patch plugin for 2017.1+, but CISA has now added it to KEV and said it is actively exploited, which conflicts with JetBrains’ earlier statement that it had seen no active exploitation. A compromised server can expose stored credentials, configurations, and build trust, and that risk reaches downstream CI/CD pipelines, not just the TeamCity box.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: in JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent…
CISA federal remediation date Aug 8
6 sources covering this story
Ra Unauthenticated RCE in Jetbrains Teamcity CVE-2026-63077
This is an unauthenticated Remote Code Execution vulnerability in JetBrains TeamCity due to unsafe deserialization in the agent polling protocol endpoint.
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
CISA says attackers are exploiting TeamCity CVE-2026-63077, an unauthenticated RCE flaw that can expose credentials and compromise build pipelines.
Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability
Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution.
Critical Code Execution Vulnerability Patched in TeamCity
Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol.
JetBrains warns of critical TeamCity remote code execution flaw
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution.
CVE-2026-63077 Critical Unauthenticated Remote Code Execution in Jetbrains Teamcity
On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises.
Rilevata vulnerabilità in JetBrains TeamCity
Rilasciato aggiornamento per risolvere una vulnerabilità di sicurezza con gravità “critica” in JetBrains TeamCity.
JetBrains fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers.
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
CVE-2026-63077 could let unauthenticated attackers bypass TeamCity checks and run OS commands; JetBrains patched all on-premises versions.
Part of the PlainSec briefing for 2026-08-15