🚨SEVERITY: CRITICAL — CVSS 9.8Security Advisory

TL;DR 📌

  • JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-05) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2026-63077.

What it is

CVE-2026-63077 is a deserialisation of untrusted data vulnerability in JetBrains TeamCity. It sits in the agent polling protocol, which handles communication between TeamCity build agents and the server.