CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
Reported exploitedTeamCityOur summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability, CVE-2026-63077, to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. This flaw affects on-premise versions of JetBrains TeamCity and stems from the improper deserialization of untrusted data within the agent polling protocol. Attackers can exploit this to bypass authentication and execute arbitrary OS commands with server-level privileges. Organizations should apply available patches promptly, with federal civilian executive branch agencies required to mitigate the issue by August 8, 2026.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.