CVE-2026-63077 – JetBrains TeamCity

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“When attackers can execute code without logging in, every exposed server becomes a priority.”

This patch addresses CVE-2026-63077, a critical vulnerability affecting JetBrains TeamCity before versions 2026.1.3 and 2025.11.7. The flaw allows unauthenticated remote code execution through the agent polling protocol, enabling a remote attacker to execute arbitrary code on a vulnerable TeamCity server without authentication.

The CVSS score is 9.8, which is Critical severity. No verified public exploitation or proof-of-concept activity has been confirmed. Due to the combination of unauthenticated access, remote code execution, and critical severity, organizations should prioritize upgrading affected TeamCity installations.

Key Details

Affected Product
Jetbrains Teamcity
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-502
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.