CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog after attackers began exploiting a critical JetBrains TeamCity On-Premises flaw that enables unauthenticated remote code execution. The vulnerability stems from deserialization of untrusted data in the TeamCity agent polling protocol and can be triggered over HTTP or HTTPS, allowing attackers to bypass authentication and execute operating system commands on exposed servers.
JetBrains said all TeamCity On-Premises versions were affected until fixes shipped in 2025.11.7 and 2026.1.3, and also released a security patch plugin for versions 2017.1 and later as a temporary mitigation path. Under BOD 26-04, CISA ordered federal civilian agencies to remediate by 2026-08-08. A successful compromise of TeamCity can expose source code, secrets, signing material, and deployment connections, raising the risk of broader software supply-chain compromise.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
Rapid7 disclosed technical details for CVE-2026-63077, identifying the root cause as TeamCity failing to clear XStream default permissions before applying its allowlist and describing an unauthenticated exploit chain via the agent polling protocol. The analysis also published indicators of compromise, including TeamCity log errors such as ConversionException, ForbiddenClassException on patched systems, and HSQLDB file I/O errors tied to attacker-written .jspws files.
CISA added CVE-2026-63077, a JetBrains TeamCity deserialization of untrusted data vulnerability, to the Known Exploited Vulnerabilities catalog. The catalog entry describes unauthenticated remote code execution via the TeamCity agent polling protocol and references vendor mitigation guidance.
CISA added CVE-2026-9198, a code injection vulnerability affecting IBM Langflow, to its Known Exploited Vulnerabilities catalog. The entry says unauthenticated attackers can achieve full remote code execution on default Langflow deployments.
CISA added CVE-2026-34486, a missing encryption of sensitive data vulnerability affecting Apache Tomcat, to its Known Exploited Vulnerabilities catalog. The entry notes the flaw can bypass the EncryptInterceptor and maps to CWE-311.
CISA added CVE-2026-18556, an authentication bypass vulnerability affecting N-able N-central, to its Known Exploited Vulnerabilities catalog. The entry identifies the issue as CWE-288 and directs stakeholders to apply vendor mitigations under BOD 26-04.
CISA warned that threat actors have started exploiting CVE-2026-63077 in JetBrains TeamCity. Public details about the attacks were not provided.
JetBrains released patched TeamCity versions 2025.11.7 and 2026.1.3 for CVE-2026-63077, and also provided a security patch plugin for TeamCity 2017.1 and later. The flaw affects TeamCity On-Premises and allows unauthenticated remote code execution via deserialization in the agent polling protocol.
JetBrains said CVE-2026-63077 in TeamCity had been reported privately. At the time of its advisory, the company said it was not aware of active exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
rapid7.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.