CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

Summary

CISA has flagged a newly patched critical vulnerability, CVE-2026-63077, in on-premise versions of JetBrains TeamCity that is being actively exploited in the wild. This flaw, rated with a CVSS score of 9.8, allows unauthenticated attackers to execute code remotely.

IFF Assessment

FOE

The active exploitation of a critical remote code execution vulnerability in a widely used CI/CD tool poses a significant threat to organizations that rely on it for their development pipelines.

Severity

9.8 Critical

The CVSS score of 9.8 indicates a critical severity, primarily due to the attack vector (network accessible) and the impact (complete compromise of confidentiality, integrity, and availability) it allows an unauthenticated attacker to achieve through deserialization of untrusted data.

CISA KEV: Listed as actively exploited. Federal patch due: August 08, 2026. Known ransomware use: Unknown.

Defender Context

This alert emphasizes the immediate need for organizations using TeamCity to apply the patch for CVE-2026-63077. Defenders should prioritize securing their CI/CD pipelines, as vulnerabilities in these systems can lead to widespread compromise and unauthorized code execution.

Read Full Story →