CVE-2026-63077: JetBrains TeamCity unauthenticated RCE with public PoC and active exploitation
github.com | vulnerability | Critical | Actively exploited | CVE-2026-63077 | #active-exploitation | #rce | #public-poc | #featured | #jetbrains | #teamcity | #deserialization | #ci-cd | #poc | #cve-2026-63077
Summary
This public PoC demonstrates unauthenticated remote code execution in JetBrains TeamCity On-Premises through the agent polling protocol and unsafe deserialization. The issue affects TeamCity On-Premises; fixes are available in 2025.11.7 and 2026.1.3. CISA added the vulnerability to KEV on August 5, 2026, confirming active exploitation. The JetBrains-hosted TeamCity service is not affected.
Why it matters
An unauthenticated attacker who can reach a TeamCity HTTP(S) service may execute arbitrary operating-system commands with the TeamCity server process privileges, exposing configuration and credentials, changing server state, and compromising build artifacts or downstream CI/CD pipelines. CISA KEV now confirms active exploitation. Upgrade to 2025.11.7, 2026.1.3, or later immediately; if upgrading is not possible, apply JetBrains' security patch plugin, restrict internet access, rotate exposed credentials, and investigate potentially exposed instances.
- CVE
- CVE-2026-63077
- Vendor
- JetBrains
- Product
- TeamCity On-Premises
- Affected versions
- All TeamCity On-Premises versions; fixed in 2025.11.7 and 2026.1.3
- CVSS
- 9.8
- Published
- Collected
Skip to content