The U.S. Cybersecurity and Infrastructure Security Agency (CISA) reports that a recently patched security vulnerability affecting on-premise versions of JetBrains TeamCity has been actively exploited in the field.
The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a case of deserialization of untrusted data that could enable an unauthenticated attacker with access to a TeamCity server to get around authentication checks and use the privileges of the TeamCity server process to execute arbitrary operating system commands.
A deserialization of untrusted data vulnerability in JetBrains TeamCity may enable unauthenticated remote code execution through the agent polling protocol, according to CISA.
JetBrains claims that an unauthenticated attacker can use the TeamCity agent polling protocol to circumvent authentication checks and carry out arbitrary operating system operations.
Depending on the rights given to the TeamCity server process, the precise effect varies. According to JetBrains, a successful attack can alter server state, reveal TeamCity data, configurations, and stored credentials, and possibly jeopardize the integrity of build artifacts read more about CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
