What it is
CVE-2026-63077 is an unauthenticated vulnerability affecting JetBrains TeamCity. In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Vulnerability report
TeamCity Remote Code Execution
JetBrains / TeamCity · affected before 2026.1.3, 2025.11.7
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-63077 is an unauthenticated vulnerability affecting JetBrains TeamCity. In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Is it exploited?
Yes. KEVIntel tracks this CVE as a known exploited vulnerability. Confidence is confirmed.
Who is affected?
JetBrains / TeamCity affected before 2026.1.3, 2025.11.7.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
CISA
Independent exploitation attestation added to the KEVIntel record.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2026-08-05 16:50 UTC |
| CVE | 2026-08-05 18:01 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Raw values available in Pro and Enterprise.
No scanner integrations recorded yet.
No KEVIntel virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.6%
Recent mention · Rapid7
OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8. An...
Read full advisoryRecent mention · Rapid7
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCityRapid7 · 29 Jul 2026
OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8. An unauthenticated remote attacker with HTTP(S) access to a TeamCity server can exploit the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.In the blog post that JetBrains shared in tandem with CVE publication, they stated...
Recent mention · TheHackerNews
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging InTheHackerNews · 28 Jul 2026
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already
Timeline
Exploitation attested by an external source
Listed in the CISA Known Exploited Vulnerabilities catalog
Vulnerability disclosed publicly
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-63077
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-63077",
"confidence": "Confirmed",
"cvss_score": 9.8,
"epss_score": 0.00649,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}