CYBERSECURITYTRACKER
TRACKING6,916 stories in this site build1,447 vulnerability news stories in this site build
Permanent story citation

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3966

As cited

Copy frozen at (site build).

vulnerabilities

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

CISA has confirmed that CVE-2026-63077, a critical remote code execution vulnerability in JetBrains TeamCity, is under active exploitation. The flaw, which affects on-premise TeamCity deployments and carries a CVSS score of 9.8, stems from unsafe deserialization of untrusted data and requires no authentication to exploit.

Why it matters: Organizations running on-premise TeamCity instances face immediate risk from unauthenticated remote code execution; apply available patches without delay.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

CISA has confirmed that CVE-2026-63077, a critical remote code execution vulnerability in JetBrains TeamCity, is under active exploitation. The flaw, which affects on-premise TeamCity deployments and carries a CVSS score of 9.8, stems from unsafe deserialization of untrusted data and requires no authentication to exploit.

Why it matters: Organizations running on-premise TeamCity instances face immediate risk from unauthenticated remote code execution; apply available patches without delay.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary