securityaffairs.com 8/6/2026, 9:32:47 AM · external

CISA puts TeamCity CVE-2026-63077 in KEV, mandates fix by August

CISA puts TeamCity CVE-2026-63077 in KEV, mandates fix by August
Developing story vulnerability 13 articles tracked
JetBrains TeamCity deserialization flaw (CVE-2026-63077) under active exploitation
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical JetBrains TeamCity vulnerability (CVE-2026-63077) to its Known Exploited Vulnerabilities catalog. This vulnerability, with a CVSS score of 9.8, allows unauthenticated attackers to execute arbitrary commands on affected servers. JetBrains has released security updates for impacted on-premises versions, while cloud instances have been patched.

Organizations are advised to upgrade to versions 2025.11.7 or 2026.1.3 or use a security patch plugin available for older versions. CISA mandates federal agencies to resolve this vulnerability by August 8, 2026.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline