CVE-2026-63077: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-08-05. EPSS: 89.6% chance of exploitation in the next 30 days.

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Affected products

  • JetBrains TeamCity: before 2025.11.7 (fixed in 2025.11.7); from 2026.1, before 2026.1.3 (fixed in 2026.1.3)

Published 2026-07-27. Last modified 2026-08-06.