logo

TeamCity RCE Flaw CVE-2026-63077 (CVSS 9.8) Enables Unauthenticated Command Execution

ID: dd192920-7597-5f83-9097-9721f5805664

STIX ID: report--dd192920-7597-5f83-9097-9721f5805664

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-07-28

Date Updated: 2026-07-29

Author: Do Son

...
...

JetBrains patched a critical unauthenticated remote code execution in TeamCity (CVE-2026-63077, CVSS 9.8) that allows attackers to execute OS commands via the agent polling protocol due to unsafe deserialization; on‑premises instances before 2026.1.3 and 2025.11.7 should be updated immediately or mitigated with official patches, network restrictions, or access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.