CISA Flags JetBrains TeamCity RCE Flaw CVE-2026-63077 Under Active Exploitation
CISA has added a critical JetBrains TeamCity remote code execution vulnerability tracked as CVE-2026-63077 to its Known Exploited Vulnerabilities catalog, with active exploitation confirmed and a tight federal patch deadline.
The U.S. Cybersecurity and Infrastructure Security Agency has flagged a critical vulnerability in JetBrains TeamCity, adding it to the Known Exploited Vulnerabilities catalog and giving federal civilian agencies a tight three-day window to apply patches. The move came on August 5, 2026, when CISA added CVE-2026-63077 to the KEV catalog with a remediation deadline of August 8 under Binding Operational Directive 26-04.
The vulnerability carries a CVSS severity score of 9.8 and stems from untrusted data deserialization, a class of flaw that lets attackers execute arbitrary code without authentication. By sending specially crafted HTTP/S requests, an unauthenticated attacker can gain full control of the TeamCity server process, making it a high-value target for initial access and lateral movement.
CISA’s inclusion in the KEV catalog explicitly confirms that the vulnerability is under active exploitation in the wild. That designation is backed by external reporting: hackers have already begun scanning for and exploiting unpatched TeamCity instances, reports SecurityWeek, activity that likely intensified once the CVE and proof-of-concept details became public.
For federal agencies, the August 8 deadline is fixed and leaves little room for testing or phased rollouts. The extreme urgency reflects the reality that unauthenticated remote code execution in a continuous integration and delivery server opens the door to supply-chain compromise, credential theft, and deep network penetration if defenders do not move immediately.
While BOD 26-04 only mandates action from federal civilian executive branch agencies, CISA has long urged all organizations—especially those supporting critical infrastructure—to treat any vulnerability in the KEV catalog as an emergency. The TeamCity flaw fits that profile: a well-understood, easily exploitable bug that gives attackers a foothold that can be difficult to detect after the fact.
Sources
- U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog — Security Affairs
- Rapid7 Analysis of CVE-2026-63077, an unauthenticated Remote Code Execution vulnerability in JetBrains TeamCity — Rapid7
- Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability — SecurityWeek
- CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild — The Hacker News