DIRAS TAKE
Urgent: this flaw was added to CISA’s Known Exploited Vulnerabilities catalog (KEV) with a short federal remediation deadline, indicating high real-world risk; prioritize deploying vendor fixes or isolating TeamCity from untrusted networks immediately.
What is CVE-2026-63077?
An unauthenticated attacker can execute arbitrary code on JetBrains TeamCity servers via the agent polling protocol (CVE-2026-63077). The flaw affects TeamCity releases before 2026.1.3 and 2025.11.7. Exploitation requires network access to the TeamCity service and no valid account or user interaction, enabling remote code execution against internet- or network-exposed instances. The weakness is classified as CWE-502 (Deserialization of Untrusted Data).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of JetBrains TeamCity are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 2026.x | before 2026.1.3, 2025.11.7 | 2026.1.3, 2025.11.7 |
Is CVE-2026-63077 being exploited?
CISA added CVE-2026-63077 to the Known Exploited Vulnerabilities catalog on 2026-08-05, and US federal civilian agencies were required to remediate it by 2026-08-08. Public exploit code is also available.
How to fix CVE-2026-63077
- Apply JetBrains updates to 2026.1.3 or 2025.11.7 immediately on affected servers.
- If you cannot update, follow JetBrains mitigations and block agent polling endpoints from untrusted networks.
- Restrict TeamCity network exposure—limit access to management interfaces to trusted IPs or VPN only.
- Monitor TeamCity and host logs for suspicious agent connections and indicators of compromise and prepare for incident response.
Frequently asked questions
Is CVE-2026-63077 being actively exploited?
Yes. CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog on 2026-08-05 and there is public exploit code; CISA required federal remediation by 2026-08-08.
Which TeamCity versions are affected by CVE-2026-63077?
TeamCity releases before 2026.1.3 and 2025.11.7 are affected according to the vendor's advisory.
Is there a patch for CVE-2026-63077?
Yes. JetBrains published fixes; update TeamCity to 2026.1.3 or 2025.11.7 to remediate the vulnerability.
Does CVE-2026-63077 require authentication?
No. The vulnerability allows unauthenticated remote code execution via the agent polling protocol and does not require a valid TeamCity account.
References
- nvd.nist.gov/vuln/detail/CVE-2026-63077
- cve.org/CVERecord?id=CVE-2026-63077
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63077
- jetbrains.com/privacy-security/issues-fixed
- All JetBrains CVEs on CVE Radar
- CVEs published in September 2026