← Vulnerability feed

Vulnerability record · CVE-2026-63077 · published 27 July 2026

CVE-2026-63077: JetBrains TeamCity unauthenticated RCE via agent polling deserialization

Jetbrains · Teamcity

JetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated remote code execution. Because the endpoint is reachable without credentials and the flaw is a deserialization issue, any internet-exposed TeamCity server is a high-value target for full compromise.

9.8 CVSS 3.1 Critical CISA KEV since 5 Aug 2026 Known ransomware use EPSS 9.8% · top 4.6% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
9.8%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
6 Aug 2026Last modified by NVD

Description

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a CVSS of 9.8, confirmed exploitation via CISA KEV and a very high EPSS score.

What it is

JetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated remote code execution. Because the endpoint is reachable without credentials and the flaw is a deserialization issue, any internet-exposed TeamCity server is a high-value target for full compromise.

Impact

An unauthenticated attacker can execute arbitrary code on the TeamCity server, gaining control of the CI/CD host and any credentials, build artifacts and deployment pipelines it manages.

Attack surface

Reached over the network through the agent polling protocol; the CVSS vector shows no privileges and no user interaction required, so no authentication is needed. Exposure depends on whether the TeamCity server or its agent communication port is reachable by the attacker.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2026-08-05 with a remediation due date of 2026-08-08, indicating active exploitation; EPSS gives a 30-day probability of 0.86518 (99.7th percentile). No ransomware campaign use is documented.

What to do

  • Upgrade TeamCity to 2026.1.3 or 2025.11.7 (or later) immediately, per the vendor advisory.
  • If patching cannot be completed before the CISA due date, restrict network access to the agent polling protocol and the TeamCity web interface to trusted hosts only.
  • Isolate the TeamCity server from production networks and limit stored credentials and deployment rights until remediation is verified.
  • Review CISA BOD 26-04 guidance and the Forensics Triage Requirements for any required triage or reporting.
  • Rotate secrets, tokens and SSH keys accessible to the TeamCity server after patching, in case of prior compromise.

Detection

  • Hunt for unexpected or anomalous connections to the TeamCity agent polling port from external or non-agent hosts.
  • Review TeamCity server logs for unusual agent registration, polling or deserialization errors around the exposure window.
  • Monitor for post-exploitation activity on the TeamCity host such as new processes spawned by the TeamCity service, outbound connections, or new scheduled tasks.
  • Check for unexpected changes to build configurations, plugins or credentials that could indicate attacker persistence.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-63077 to the Known Exploited Vulnerabilities catalog on 5 August 2026 as "JetBrains TeamCity Deserialization of Untrusted Data Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 8 August 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-63077 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-27198JetBrains TeamCity authentication bypass allows admin actionsJetBrains TeamCity before 2023.11.4 contains an authentication bypass via an alternate path (CWE-288), letting an unauthenticated attacker reach func…KEVEPSS 100%analysed9.8CVE-2023-42793JetBrains TeamCity authentication bypass leads to remote code executionJetBrains TeamCity before 2023.05.4 contains an authentication bypass via an alternate path, classified as CWE-288 and CWE-306, that allows an unauth…KEVEPSS 100%analysed7.3CVE-2024-27199JetBrains TeamCity path traversal enables limited admin actionsJetBrains TeamCity before 2023.11.4 is vulnerable to relative path traversal that lets an unauthenticated remote party perform limited administrative…KEVEPSS 100%analysed10.0CVE-2026-65906Jetbrains teamcity code injection vulnerabilityIn JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possibleEPSS 0.66%9.8CVE-2025-54530Jetbrains teamcity incorrect default permissions vulnerabilityIn JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissionsEPSS 0.18%9.8CVE-2025-46433Jetbrains teamcity relative path traversal vulnerabilityIn JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possibleEPSS 0.55%9.8CVE-2024-41827Jetbrains teamcity insufficient session expiration vulnerabilityIn JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expirationEPSS 0.40%9.8CVE-2024-36470Jetbrains teamcity authentication bypass via alternate path vulnerabilityIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge casesEPSS 0.46%

Source: NIST National Vulnerability Database (record CVE-2026-63077), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.