CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CISA Flags JetBrains TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation

August 6, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly patched critical vulnerability in JetBrains TeamCity to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. The flaw, tracked as CVE-2026-63077 (CVSS score: 9.8), is a deserialization of untrusted data vulnerability that allows an unauthenticated attacker to bypass authentication and execute arbitrary operating system commands on the TeamCity server.

According to JetBrains, the vulnerability can be exploited via the TeamCity agent polling protocol. A successful attack could expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise build artifacts and downstream CI/CD pipelines. The exact impact depends on the privileges granted to the TeamCity server process.

While the identity of the threat actors and the scale of exploitation remain unknown, CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies patch the vulnerability by August 8, 2026, per Binding Operational Directive (BOD) 26-04. Organizations running on-premise versions of TeamCity are strongly advised to apply the available updates immediately.

CVEs: CVE-2026-63077, CVE-2026-50522

Companies: JetBrains, CISA

Products: TeamCity