CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
August 6, 2026 · The Hacker News · Severity: HIGH
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged CVE-2026-63077, a critical remote code execution (RCE) vulnerability in JetBrains TeamCity, as actively exploited in the wild. This flaw, with a CVSS score of 9.8, stems from deserialization of untrusted data, enabling unauthenticated attackers to bypass authentication checks and execute arbitrary commands on TeamCity servers. The vulnerability affects on-premise versions of TeamCity and can lead to unauthorized access to server data, configurations, credentials, and potentially compromise build artifacts and CI/CD pipelines. JetBrains confirmed that attackers can exploit the flaw via the TeamCity agent polling protocol, though details about the exploitation methods, threat actors, and the scale of attacks remain unclear. Federal Civilian Executive Branch agencies are mandated to patch the vulnerability by August 8, 2026, under CISA’s Binding Operational Directive 26-04. Organizations using on-premise TeamCity instances are urged to apply updates immediately to mitigate risks. This vulnerability highlights the critical need for timely patching to prevent potential breaches and safeguard sensitive data.
Key Takeaways
- CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, warning of active exploitation targeting JetBrains TeamCity servers.
- The vulnerability allows remote code execution on unpatched TeamCity instances, which are commonly used in CI/CD pipelines and software delivery.
- JetBrains has addressed the flaw in the latest TeamCity release — organizations should update immediately and check for signs of compromise.