A critical vulnerability in JetBrains TeamCity, identified as CVE-2026-63077, allows unauthenticated remote code execution, enabling attackers to execute operating system commands with the same privileges as the TeamCity server process. This unsafe deserialization vulnerability can be exploited by attackers who can reach the TeamCity server over HTTP or HTTPS, without requiring any credentials. Although JetBrains initially reported no known active exploitation, the vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on August 5, 20261, indicating potential active exploitation. The vulnerability affects TeamCity servers, allowing attackers to gain control and execute malicious commands. This vulnerability matters to practitioners because its exploitation status determines the urgency of patching, making it essential to monitor and address the vulnerability promptly to prevent potential attacks.
Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
⚠️ Critical Alert
Why This Matters
CVE-2026-63077 is in active discussion involving CISA — exploitation status determines whether this is patch-now or monitor.
References
- Rapid7. (2026, August 7). Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077). Rapid7 Blog. https://www.rapid7.com/blog/post/ra-unauthenticated-rce-in-jetbrains-teamcity-cve-2026-63077
Original Source
Rapid7 Blog
Read original →