CVE-2026-63077: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
Summary
JetBrains TeamCity has a deserialization vulnerability (CVE-2026-63077) that allows unauthenticated remote code execution through its agent polling protocol. Users are instructed to apply vendor-provided mitigations and comply with CISA's directives on prioritizing security updates.
IFF Assessment
This vulnerability allows unauthenticated remote code execution, posing a significant threat to systems and data.
Severity
The vulnerability allows for unauthenticated remote code execution, has a high attack complexity, and can lead to complete system compromise, indicated by a CVSS score of 9.8 (Critical).
CISA KEV: Listed as actively exploited. Federal patch due: August 08, 2026. Known ransomware use: Unknown.
Defender Context
This critical vulnerability in JetBrains TeamCity presents a significant risk for organizations using the software, as it allows for remote code execution without authentication. Defenders must prioritize applying vendor-provided mitigations and adhere to CISA's guidance on risk-based patching to prevent potential exploitation by threat actors, especially considering the known ransomware use is unknown, suggesting potential for novel attacks.