Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-63077

JetBrains TeamCity On-Prem Unauthenticated RCE

CVSS 9.8 critical. Unauthenticated remote code execution in all JetBrains TeamCity On-Premises versions, fixed in 2025.11.7 and 2026.1.3.

cat cve-2026-63077.json
Vendor
JetBrains
Product
TeamCity On-Premises (all versions)
CVSS
9.8
EPSS (exploit probability)
86.5%
Status
kev
CISA patch-by (BOD 22-01)
Published

Unauthenticated remote code execution in all on-premises versions of JetBrains TeamCity. A remote attacker with network access to the TeamCity port can execute arbitrary operating system commands on the host server without any credentials.

Fixed in 2025.11.7 (LTS branch) and 2026.1.3 (current branch). TeamCity Cloud was patched automatically.

CISA added CVE-2026-63077 to the Known Exploited Vulnerabilities catalog on August 5, 2026, with a federal remediation deadline of August 8. Active exploitation is confirmed: attackers breached JetBrains’ own Cadence ML platform using this flaw between August 8 and August 23, extracting AWS IAM credentials, a full server backup, and PyCharm project source code. Rapid7 identified the TeamCity agent-listener protocol as a secondary attack surface beyond the main RCE path.

Consult JetBrains security advisories and the NVD entry for current status.