securityonline.info 8/6/2026, 3:21:23 AM · external

CISA adds TeamCity RCE flaw CVE-2026-63077 to KEV, patch by Aug 8

CISA adds TeamCity RCE flaw CVE-2026-63077 to KEV, patch by Aug 8
Developing story vulnerability 8 articles tracked
JetBrains TeamCity deserialization flaw (CVE-2026-63077) allows unauthenticated RCE
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

CISA has added the TeamCity vulnerability CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, allowing unauthenticated remote code execution on TeamCity On-Premises servers. Federal agencies must patch affected versions by August 8, 2026. The vulnerability has a CVSS score of 9.8 and impacts TeamCity versions below 2026.1.3 and 2025.11.7. The flaw arises from insecure deserialization of untrusted data, enabling attackers to execute commands with server privileges.

JetBrains has provided patches in recent versions. For those unable to upgrade, a security patch plugin is available for older versions, and server access should be restricted.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline