CVE-2026-63077: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

Summary

JetBrains TeamCity has a deserialization vulnerability (CVE-2026-63077) that allows unauthenticated remote code execution through its agent polling protocol. Users are instructed to apply vendor-provided mitigations and comply with CISA's directives on prioritizing security updates.

IFF Assessment

FOE

This vulnerability allows unauthenticated remote code execution, posing a significant threat to systems and data.

Severity

9.8 Critical

The vulnerability allows for unauthenticated remote code execution, has a high attack complexity, and can lead to complete system compromise, indicated by a CVSS score of 9.8 (Critical).

CISA KEV: Listed as actively exploited. Federal patch due: August 08, 2026. Known ransomware use: Unknown.

Defender Context

This critical vulnerability in JetBrains TeamCity presents a significant risk for organizations using the software, as it allows for remote code execution without authentication. Defenders must prioritize applying vendor-provided mitigations and adhere to CISA's guidance on risk-based patching to prevent potential exploitation by threat actors, especially considering the known ransomware use is unknown, suggesting potential for novel attacks.

Read Full Story →