Unauthenticated Remote Code Execution in JetBrains TeamCity by JetBrains
CVE-2026-63077
Key Information:
Badges
What is CVE-2026-63077?
CVE-2026-63077 is a severe vulnerability discovered in JetBrains TeamCity, a widely-used continuous integration and deployment server that facilitates software development and project management. This vulnerability allows unauthenticated remote code execution via the agent polling protocol in versions prior to 2026.1.3 and 2025.11.7. The flaw poses a significant risk to organizations as an attacker could potentially exploit it to execute arbitrary code on the server without any prior authentication. This compromise can lead to unauthorized access and control of the development environment, data manipulation, or even deployment of malicious artifacts into production systems, greatly affecting the integrity and security of software development processes.
Potential impact of CVE-2026-63077
-
Unauthorized Access and Code Execution: The ability for attackers to execute arbitrary code on a vulnerable TeamCity instance means that they could manipulate software builds, introduce malicious code into applications, or escalate their privileges within the organizational network.
-
Data Breaches: Exploitation of this vulnerability may result in exposure of sensitive information, such as source code, proprietary algorithms, and other intellectual property stored within the TeamCity environment, which could be detrimental to an organization’s competitive edge and reputation.
-
Operational Disruptions: An attacker gaining control over the build and deployment processes could lead to disruptions in software delivery, affecting project timelines and the reliability of software products. This could also result in financial losses and damage to client trust.
CISA has reported CVE-2026-63077
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-63077 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
TeamCity 0 < 2026.1.3, 2025.11.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Java News Roundup: Shenandoah GC, TeamCity CVE, A2A Java SDK, Camel, Gradle, GlassFish, Groovy
This week's Java roundup for August 3rd, 2026, features news highlighting: JEP 535, Shenandoah GC: Generational Mode by Default, targeted for JDK 28; point releases of A2A Java SDK, Apache Camel and G
1 week ago
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild - IT Security News
Vendors can use your data to provide services. Declining a vendor can stop them from using the data you shared.Exponential Interactive, Inc d/b/a VDX.tvCookie duration: 90 (days).Data collected and processed:...
2 weeks ago
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
CISA says attackers are exploiting TeamCity CVE-2026-63077, an unauthenticated RCE flaw that can expose credentials and compromise build pipelines.
2 weeks ago
References
EPSS Score
10% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 🦅
CISA Reported
- 📈
Vulnerability started trending
- 👾
Exploit known to exist
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved