JetBrains disclosed CVE-2026-63077, a critical remote code execution flaw in TeamCity On-Premises that lets unauthenticated attackers with HTTP(S) access abuse the agent polling protocol to bypass authentication and run arbitrary operating system commands. The vulnerability affects TeamCity versions before 2026.1.3 and 2025.11.7, carries a CVSS 3.1 rating of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), and is mapped to CWE-502.
JetBrains released fixes in 2025.11.7 and 2026.1.3, and also published a security patch plugin for TeamCity versions 2017.1 and later for organizations that cannot upgrade immediately. TeamCity Cloud instances were already updated, while JetBrains said it has no evidence of active exploitation; CISA’s SSVC assessment likewise indicates no known exploitation but notes the bug is automatable and could have total technical impact. Successful attacks could expose TeamCity data, configurations, and stored credentials, or allow modification of server state depending on the privileges of the TeamCity process.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, confirming active exploitation of the TeamCity flaw. This represented an escalation from earlier assessments that noted no known exploitation.
JetBrains said the TeamCity RCE vulnerability CVE-2026-63077 was privately reported by Antoni Tremblay. This establishes the initial vendor notification before public disclosure and patch release.
CISA added an SSVC assessment for CVE-2026-63077 indicating no known exploitation, that exploitation would be automatable, and that the technical impact would be total. This added government risk-triage context to the vulnerability record.
JetBrains fixed CVE-2026-63077 in TeamCity versions 2025.11.7 and 2026.1.3. It also released a security patch plugin for TeamCity 2017.1 and later for customers unable to upgrade immediately, while TeamCity Cloud instances were already updated.
JetBrains disclosed a critical unauthenticated remote code execution flaw in TeamCity On-Premises, tracked as CVE-2026-63077, involving the agent polling protocol. The issue affects TeamCity versions before 2025.11.7 and 2026.1.3, and JetBrains said it had no evidence of active exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
23 references tracked. Mallory keeps watching after this page renders.
triskelelabs.com
Open sourceboho.or.kr
Open sourcecybersecuritynews.com
Open sourceinfoworld.com
Open sourcecve.org
Open sourcecvefeed.io
Open sourceblog.jetbrains.com
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.