logo

CVE-2026-63077: TeamCity RCE Flaw Exploited in the Wild, CISA Warns

ID: 0a75cfc0-cc8c-55a7-b820-fc0ed6e09eab

STIX ID: report--0a75cfc0-cc8c-55a7-b820-fc0ed6e09eab

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: Do Son

...
...

**CVE-2026-63077 – JetBrains TeamCity (On-Premises)**: A critical (CVSS 9.8) unauthenticated deserialization RCE in TeamCity agent polling allows remote attackers to execute OS commands as the server process; CISA added it to the KEV catalog with a federal remediation deadline and JetBrains released fixes in 2026.1.3 and 2025.11.7 (TeamCity Cloud already patched).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.