CVE-2026-63077 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-63077 | CVSS 9.8 (Critical) | Exploit: PoC available
What Is It
CVE-2026-63077 is a critical unauthenticated remote code execution vulnerability in the agent polling protocol of JetBrains TeamCity before versions 2026.1.3 and 2025.11.7.
Technical Detail
The vulnerability allows an unauthenticated remote attacker to exploit the TeamCity agent polling protocol and execute arbitrary code on a vulnerable TeamCity server. Successful exploitation does not require valid TeamCity credentials. The available information does not identify the underlying flaw class or a specific malformed request required to trigger the issue.
Exploitation Status
A proof of concept is available. CISA has not added CVE-2026-63077 to the Known Exploited Vulnerabilities Catalog, and active exploitation in the wild has not been confirmed by the provided data.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize patching TeamCity servers to version 2026.1.3, 2025.11.7, or a later supported release. Until updates can be applied, restrict access to TeamCity agent polling endpoints to trusted build agents and approved network paths, and do not expose the TeamCity server or agent communication interfaces directly to the internet. Review TeamCity server logs, reverse-proxy logs, and endpoint telemetry for unexpected requests to agent polling endpoints, anomalous child processes spawned by TeamCity services, and unauthorized changes to build configurations, agents, credentials, or server files. No vendor workaround or specific detection signature is confirmed in the provided data.