• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-63077: pre-auth remote code execution in JetBrains TeamCity

An unauthenticated attacker can execute arbitrary code on JetBrains TeamCity servers via the agent polling protocol (CVE-2026-63077). The flaw affects TeamCity releases before 2026.1.3 and 2025.11.7. Exploitation requires network access to the TeamCity service and no valid account or user interaction, enabling remote code execution against internet- or network-exposed instances.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.8957
CWE
CWE-502
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: this flaw was added to CISA’s Known Exploited Vulnerabilities catalog (KEV) with a short federal remediation deadline, indicating high real-world risk; prioritize deploying vendor fixes or isolating TeamCity from untrusted networks immediately.

What is CVE-2026-63077?

An unauthenticated attacker can execute arbitrary code on JetBrains TeamCity servers via the agent polling protocol (CVE-2026-63077). The flaw affects TeamCity releases before 2026.1.3 and 2025.11.7. Exploitation requires network access to the TeamCity service and no valid account or user interaction, enabling remote code execution against internet- or network-exposed instances. The weakness is classified as CWE-502 (Deserialization of Untrusted Data).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of JetBrains TeamCity are affected?

BRANCHAFFECTEDFIXED
2026.xbefore 2026.1.3, 2025.11.72026.1.3, 2025.11.7

Is CVE-2026-63077 being exploited?

CISA added CVE-2026-63077 to the Known Exploited Vulnerabilities catalog on 2026-08-05, and US federal civilian agencies were required to remediate it by 2026-08-08. Public exploit code is also available.

How to fix CVE-2026-63077

  1. Apply JetBrains updates to 2026.1.3 or 2025.11.7 immediately on affected servers.
  2. If you cannot update, follow JetBrains mitigations and block agent polling endpoints from untrusted networks.
  3. Restrict TeamCity network exposure—limit access to management interfaces to trusted IPs or VPN only.
  4. Monitor TeamCity and host logs for suspicious agent connections and indicators of compromise and prepare for incident response.

Frequently asked questions

Is CVE-2026-63077 being actively exploited?

Yes. CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog on 2026-08-05 and there is public exploit code; CISA required federal remediation by 2026-08-08.

Which TeamCity versions are affected by CVE-2026-63077?

TeamCity releases before 2026.1.3 and 2025.11.7 are affected according to the vendor's advisory.

Is there a patch for CVE-2026-63077?

Yes. JetBrains published fixes; update TeamCity to 2026.1.3 or 2025.11.7 to remediate the vulnerability.

Does CVE-2026-63077 require authentication?

No. The vulnerability allows unauthenticated remote code execution via the agent polling protocol and does not require a valid TeamCity account.

References