www.securityweek.com 8/6/2026, 6:41:25 AM · external

JetBrains patches TeamCity deserialization flaw after CISA alert

JetBrains patches TeamCity deserialization flaw after CISA alert
Developing story vulnerability 10 articles tracked
JetBrains TeamCity deserialization flaw (CVE-2026-63077) exploited in the wild
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

THREAT actors are exploiting a recently patched vulnerability in JetBrains TeamCity, a critical CI/CD platform. The vulnerability, tracked as CVE-2026-63077 with a CVSS score of 9.8, is related to deserialization of untrusted data, allowing unauthenticated attackers to achieve remote code execution via HTTP/S requests. This issue affects all TeamCity On-Premises versions, enabling attackers to bypass authentication checks and execute arbitrary commands with the TeamCity server's privileges.

JetBrains has urged organizations to apply patches included in versions 2025.11.7 and 2026.1.3. The U.S. cybersecurity agency CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, advising federal agencies to patch it within three days. Currently, no active exploitation has been reported.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline