JetBrains TeamCity Critical RCE Flaw CVE-2026-63077 Actively Exploited in the Wild
A critical unauthenticated remote code execution vulnerability, tracked as CVE-2026-63077, has been discovered in JetBrains TeamCity On-Premises and is being actively exploited by attackers. The flaw resides in the agent polling protocol, allowing threat actors to send crafted serialized data over HTTP or HTTPS without any authentication and execute arbitrary OS commands with TeamCity server-level privileges. Successful exploitation can expose build secrets, stored credentials, source configurations, and artifacts, and may enable attackers to tamper with pipelines or distribute malicious builds in a supply-chain attack. JetBrains has released fixed versions 2025.11.7 and 2026.1.3, along with a security patch plugin supporting installations from version 2017.1 onward. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, and administrators are urged to patch immediately or restrict server access to trusted networks via VPN or allowlist.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in