CISA_KEV · AUGUST 2026 · CONFIRMED

JetBrains TeamCity RCE Vulnerability CVE-2026-63077 Under Active Exploitation

CVE-2026-63077Severity: CRITICAL

CISA has confirmed that the critical deserialization vulnerability CVE-2026-63077 in JetBrains TeamCity is being actively exploited in the wild. This vulnerability allows unauthenticated remote code execution.

What happened

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged CVE-2026-63077, a critical deserialization vulnerability in JetBrains TeamCity, as being actively exploited. This vulnerability, with a CVSS score of 9.8, enables unauthenticated remote code execution via the agent polling protocol. According to CISA, an attacker can exploit this flaw to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. The impact of a successful attack can include exposure of TeamCity data, configurations, and stored credentials, modification of server state, and potential compromise of build artifacts and downstream CI/CD pipelines.

JetBrains has advised users of on-premise versions of TeamCity to apply the latest updates immediately to mitigate the risk. The exact methods of exploitation in the wild, the identities of the threat actors, and the scale of the attacks remain unknown. For more detailed information, it is recommended to consult the primary sources provided by CISA and other cybersecurity news platforms.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If jetbrains teamcity is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats