Exploited in the wild TeamCity rce JetBrains
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
CVE Tools coverage
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability, CVE-2026-63077, to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. This flaw affects on-premise versions of JetBrains TeamCity and stems from the improper deserialization of untrusted data within the agent polling protocol. Attackers can exploit this to bypass authentication and execute arbitrary OS commands with server-level privileges. Organizations should apply available patches promptly, with federal civilian executive branch agencies required to mitigate the issue by August 8, 2026.