CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
ID: d590c436-1be5-5dab-866a-4849aeb300f3
STIX ID: report--d590c436-1be5-5dab-866a-4849aeb300f3
Feed Name: The Hacker News
Threat Score
## Executive summary A critical deserialization vulnerability (CVE-2026-63077, CVSS 9.8) in on‑premises JetBrains TeamCity enables unauthenticated remote code execution via the agent polling protocol; CISA reports active exploitation in the wild. JetBrains warns the flaw can expose data, stored credentials, and compromise build integrity; affected users are urged to apply patches immediately, with U.S. federal agencies required to remediate by August 8, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
