logo

PoC Releases for CVE-2026-63077: TeamCity RCE Exploited in the Wild

ID: 94590b69-f344-5468-9d7b-da75d28b8ca0

STIX ID: report--94590b69-f344-5468-9d7b-da75d28b8ca0

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-08-10

Date Updated: 2026-08-10

Author: Do Son

...
...

A critical unauthenticated remote code execution vulnerability (CVE-2026-63077) in JetBrains TeamCity arises from unsafe XStream deserialization in the agent polling protocol; CISA confirmed exploitation in the wild and public proof-of-concept code is available, while JetBrains has released patches (2026.1.3, 2025.11.7) — administrators should update immediately and review agent logs for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.