Unauthenticated Remote Code Execution in JetBrains TeamCity by JetBrains
CVE-2026-63077

9.8CRITICAL

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
27 July 2026

Badges

📈 Trended📈 Score: 2,520💰 Ransomware👾 Exploit Exists🟡 Public PoC🟣 EPSS 89%🦅 CISA Reported📰 News Worthy

What is CVE-2026-63077?

CVE-2026-63077 is a severe vulnerability discovered in JetBrains TeamCity, a widely-used continuous integration and deployment server that facilitates software development and project management. This vulnerability allows unauthenticated remote code execution via the agent polling protocol in versions prior to 2026.1.3 and 2025.11.7. The flaw poses a significant risk to organizations as an attacker could potentially exploit it to execute arbitrary code on the server without any prior authentication. This compromise can lead to unauthorized access and control of the development environment, data manipulation, or even deployment of malicious artifacts into production systems, greatly affecting the integrity and security of software development processes.

Potential impact of CVE-2026-63077

  1. Unauthorized Access and Code Execution: The ability for attackers to execute arbitrary code on a vulnerable TeamCity instance means that they could manipulate software builds, introduce malicious code into applications, or escalate their privileges within the organizational network.

  2. Data Breaches: Exploitation of this vulnerability may result in exposure of sensitive information, such as source code, proprietary algorithms, and other intellectual property stored within the TeamCity environment, which could be detrimental to an organization’s competitive edge and reputation.

  3. Operational Disruptions: An attacker gaining control over the build and deployment processes could lead to disruptions in software delivery, affecting project timelines and the reliability of software products. This could also result in financial losses and damage to client trust.

CISA has reported CVE-2026-63077

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-63077 as being exploited and is known by the CISA as enabling ransomware campaigns.

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

TeamCity 0 < 2026.1.3, 2025.11.7

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

CISA: Ransomware gangs now exploiting critical TeamCity flaw

​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July.

1 week ago

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

Attackers exploited CVE-2026-63077 to breach JetBrains Cadence, accessing a 2024 backup containing credentials and user data.

1 month ago

Java News Roundup: Shenandoah GC, TeamCity CVE, A2A Java SDK, Camel, Gradle, GlassFish, Groovy

This week's Java roundup for August 3rd, 2026, features news highlighting: JEP 535, Shenandoah GC: Generational Mode by Default, targeted for JDK 28; point releases of A2A Java SDK, Apache Camel and G

References

EPSS Score

89% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 💰

    Used in Ransomware

  • 🦅

    CISA Reported

  • 📈

    Vulnerability started trending

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.