CISA KEV Alert 8/5/2026, 6:31:29 PM

CISA flags critical JetBrains TeamCity flaw CVE‑2026‑63077 in KEV

Developing story vulnerability 7 articles tracked
JetBrains TeamCity deserialization flaw (CVE-2026-63077) allows unauthenticated RCE
CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

ON 5 August 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE‑2026‑63077 to its Known Exploited Vulnerabilities (KEV) catalogue. The flaw affects JetBrains TeamCity and is named the JetBrains TeamCity Deserialization of Untrusted Data Vulnerability. It allows unauthenticated remote code execution via the agent polling protocol.

The vulnerability is a deserialization of untrusted data issue in TeamCity’s agent polling interface. An attacker who can send crafted data to the protocol can achieve arbitrary code execution on the server without authentication. The Common Vulnerability Scoring System assigns it a base score of 9.8, rating it as critical. No patch or advisory has been made public at the time of writing, and the patch status is listed as unknown.

CISA’s inclusion in the KEV catalogue confirms that the vulnerability is being actively exploited in the wild. There is no publicly known link to ransomware campaigns at this time. Federal Civilian Executive Branch (FCEB) agencies must apply mitigations by the remediation due date of 8 August 2026.

CISA directs FCEB agencies to apply mitigations in accordance with JetBrains guidance, ensure compliance with BOD 26‑04 Prioritizing Security Updates Based on Risk and the Forensics Triage Requirements, follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable, and evaluate each asset's internet exposure to adhere to BOD 26‑04 patching guidelines. All other organisations should review their TeamCity deployments for exposure and apply any available mitigations.

For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-63077 and the CISA KEV catalogue.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline