top of page
perceptive_background_267k.jpg

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

Published:

6 August 2026 at 08:51:43

Alert date:

6 August 2026 at 11:03:45

Source:

thehackernews.com

Click to open the original link from this advisory

Enterprise Applications, Zero-Day Vulnerabilities, Supply Chain & Dependencies

CISA has flagged CVE-2026-63077, a critical remote code execution vulnerability in JetBrains TeamCity on-premise versions, as being actively exploited in the wild. The flaw carries a CVSS score of 9.8 and stems from deserialization of untrusted data. An unauthenticated attacker with access to a TeamCity server can potentially exploit this vulnerability to execute arbitrary code. JetBrains has released a patch addressing the issue. CISA's flagging of the vulnerability signals urgent remediation is required for affected organizations. The flaw poses significant risk to software development pipelines and CI/CD infrastructure globally.

Technical details

CVE-2026-63077 is a critical deserialization of untrusted data vulnerability in JetBrains TeamCity on-premise versions with a CVSS score of 9.8. An unauthenticated remote attacker can exploit this flaw via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. A successful exploit can expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines. The exact exploitation method in the wild, threat actor identity, and scale of attacks are currently unknown.

Mitigation steps:

Apply the latest patches for JetBrains TeamCity on-premise versions as soon as possible. Federal Civilian Executive Branch (FCEB) agencies are required under Binding Operational Directive (BOD) 26-04 to remediate CVE-2026-63077 by August 8, 2026, as it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Monitor the CISA KEV catalog and JetBrains advisories for further updates on exploitation details and additional mitigations.

Affected products:

JetBrains TeamCity (on-premise versions)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page