CISA has added the TeamCity vulnerability CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, allowing unauthenticated remote code execution on TeamCity On-Premises servers. Federal agencies must patch affected versions by August 8, 2026. The vulnerability has a CVSS score of 9.8 and impacts TeamCity versions below 2026.1.3 and 2025.11.7. The flaw arises from insecure deserialization of untrusted data, enabling attackers to execute commands with server privileges.
JetBrains has provided patches in recent versions. For those unable to upgrade, a security patch plugin is available for older versions, and server access should be restricted.