TeamCity RCE Flaw CVE-2026-63077 (CVSS 9.8) Enables Unauthenticated Command Execution
ID: dd192920-7597-5f83-9097-9721f5805664
STIX ID: report--dd192920-7597-5f83-9097-9721f5805664
Feed Name: securityonline.info
Threat Score
JetBrains patched a critical unauthenticated remote code execution in TeamCity (CVE-2026-63077, CVSS 9.8) that allows attackers to execute OS commands via the agent polling protocol due to unsafe deserialization; on‑premises instances before 2026.1.3 and 2025.11.7 should be updated immediately or mitigated with official patches, network restrictions, or access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
