CVE- 2026-63077 is a critical unauthenticated remote code execution vulnerability in JetBrains TeamCity, allowing attackers to execute OS commands without credentials. Confirmed by CISA, this flaw has been exploited in the wild, with both detailed vulnerability information and proof-of-concept exploit code publicly released. Affected versions include TeamCity versions before 2026.1.3 and 2025.11.7, with fixes provided in these versions.
The vulnerability arises from unsafe deserialization in the agent polling protocol. Rapid7 has demonstrated exploitation methods, confirming risks to system integrity and build processes. Immediate upgrade to the patched versions is recommended.