NPM · AUGUST 2026 · EARLY WARNING

TeamCity CVE-2026-63077 Under Active Exploitation: Critical Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-63077Severity: CRITICAL

An early warning has been issued regarding a critical vulnerability, CVE-2026-63077, in JetBrains TeamCity, which is reportedly under active exploitation. On-premise TeamCity users are advised to upgrade immediately.

What happened

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reported that a newly patched security flaw in on-premise versions of JetBrains TeamCity, identified as CVE-2026-63077, is being actively exploited. This vulnerability involves deserialization of untrusted data, allowing unauthenticated attackers to execute arbitrary operating system commands via the TeamCity agent polling protocol. The exact methods of exploitation, the identities of the threat actors, and the scale of the attacks remain unknown. JetBrains has not yet confirmed the active exploitation in their advisory.

The potential impact of a successful attack includes exposure of TeamCity data, configurations, and stored credentials, modification of server state, and compromise of build artifacts and downstream CI/CD pipelines. The severity of the impact depends on the privileges granted to the TeamCity server process.

Professional software engineers using on-premise versions of TeamCity are urged to upgrade to the latest version as soon as possible. Additionally, it is recommended to ensure that no untrusted data is being deserialized. For more detailed information, consult the primary sources provided.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If teamcity is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats