logo

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

ID: d590c436-1be5-5dab-866a-4849aeb300f3

STIX ID: report--d590c436-1be5-5dab-866a-4849aeb300f3

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: [email protected] (The Hacker News)

...
...

## Executive summary A critical deserialization vulnerability (CVE-2026-63077, CVSS 9.8) in on‑premises JetBrains TeamCity enables unauthenticated remote code execution via the agent polling protocol; CISA reports active exploitation in the wild. JetBrains warns the flaw can expose data, stored credentials, and compromise build integrity; affected users are urged to apply patches immediately, with U.S. federal agencies required to remediate by August 8, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.