
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-63077 is a critical unauthenticated remote code execution (RCE) vulnerability in JetBrains TeamCity On-Premises, exploitable via the agent polling protocol. It affects all TeamCity versions before 2026.1.3 and before 2025.11.7. The vulnerability was published on July 27, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, CISA KEV).
The root cause is improper deserialization of untrusted data (CWE-502) within TeamCity's agent polling protocol — the communication channel used by build agents to check in with the TeamCity server. An unauthenticated remote attacker can send a specially crafted HTTP request to this protocol endpoint, triggering unsafe Java deserialization that results in arbitrary OS command execution on the server. No authentication, user interaction, or special privileges are required, making the attack fully automatable. A public technical analysis and PoC exploit were published by Rapid7 researcher Stephen Fewer (GitHub: sfewer-r7/CVE-2026-63077), and a Metasploit module pull request was subsequently submitted (Rapid7 Analysis, GitHub Advisory).
Successful exploitation grants an unauthenticated attacker full remote code execution on the TeamCity server as the service account, resulting in complete compromise of confidentiality, integrity, and availability. Because TeamCity is a CI/CD platform, a compromised server can expose source code, build secrets, API keys, and deployment credentials, enabling downstream supply chain attacks against any software built or deployed through the platform. Attackers can also use the foothold for lateral movement within the internal network, persistence via backdoors, or ransomware deployment (CISA KEV, Rapid7 Analysis).
Active in-the-wild exploitation was confirmed and CVE-2026-63077 was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 5, 2026, with a remediation due date of August 8, 2026 (CISA KEV). A public PoC and full technical analysis were released by Rapid7's Stephen Fewer on August 7, 2026, including a GitHub repository (sfewer-r7/CVE-2026-63077) and a Metasploit module pull request (Rapid7 Analysis). A network packet capture (PCAP) of exploitation traffic was also published (BoredHackerBlog/teamcity-CVE-2026-63077-pcap). The EPSS score is approximately 10.7% (95th percentile) per the GitHub Advisory, and NVD's SSVC assessment classifies exploitation as active and automatable with total technical impact (GitHub Advisory). No specific threat actor attribution has been publicly confirmed at this time.
cmd.exe, powershell.exe, /bin/bash, curl, wget, python); new scheduled tasks or cron jobs created by the TeamCity service account.BoredHackerBlog/teamcity-CVE-2026-63077-pcap) can be used to develop network signatures (Rapid7 Analysis, CISA KEV).JetBrains has released patched versions: TeamCity 2026.1.3 and TeamCity 2025.11.7. All organizations running TeamCity On-Premises should upgrade immediately to one of these versions. CISA's BOD 26-04 required federal agencies to remediate by August 8, 2026. If immediate patching is not possible, restrict network access to the TeamCity server's agent polling port to only known, trusted build agent IP addresses as a temporary mitigation. TeamCity Cloud is not affected. JetBrains published an update blog post with additional guidance (JetBrains Blog, CISA KEV, JetBrains Security).
JetBrains published an official update blog post on August 7, 2026, acknowledging active exploitation and urging immediate patching (JetBrains Blog). Rapid7 researcher Stephen Fewer published a detailed technical analysis and PoC on August 7, 2026, which generated significant attention on security social media platforms including Twitter/X and Mastodon (Rapid7 Analysis). The Hacker News, BleepingComputer, SecurityWeek, SC World, and Security Affairs all covered the vulnerability and CISA's KEV addition extensively. Community discussion on Reddit (r/SecOpsDaily, r/CyberNews, r/linuxadmin, r/crowdstrike) reflected significant concern about CI/CD supply chain risk, with practitioners sharing detection and remediation guidance. The Canadian Centre for Cyber Security (CCCS) and NHS Digital also issued advisories, reflecting broad international concern.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."