Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-63077: JetBrains TeamCity unauthenticated RCE with public PoC and active exploitation

Summary

This public PoC demonstrates unauthenticated remote code execution in JetBrains TeamCity On-Premises through the agent polling protocol and unsafe deserialization. The issue affects TeamCity On-Premises; fixes are available in 2025.11.7 and 2026.1.3. CISA added the vulnerability to KEV on August 5, 2026, confirming active exploitation. The JetBrains-hosted TeamCity service is not affected.

Why it matters

An unauthenticated attacker who can reach a TeamCity HTTP(S) service may execute arbitrary operating-system commands with the TeamCity server process privileges, exposing configuration and credentials, changing server state, and compromising build artifacts or downstream CI/CD pipelines. CISA KEV now confirms active exploitation. Upgrade to 2025.11.7, 2026.1.3, or later immediately; if upgrading is not possible, apply JetBrains' security patch plugin, restrict internet access, rotate exposed credentials, and investigate potentially exposed instances.
CVE
CVE-2026-63077
Vendor
JetBrains
Product
TeamCity On-Premises
Affected versions
All TeamCity On-Premises versions; fixed in 2025.11.7 and 2026.1.3
CVSS
9.8
Published
Collected

original ↗