SYS::ONLINE
Wasteland.
Briefs1722
Issues22
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-63077 2026-08-05

JetBrains TeamCity Hit With Unauthenticated RCE — CVE-2026-63077 Added to CISA KEV

"CISA added CVE-2026-63077, a critical (CVSS 9.8) deserialization flaw in JetBrains TeamCity allowing unauthenticated remote code execution, to its Known Exploited Vulnerabilities catalog on August 5, 2026, with a…"

CISA added CVE-2026-63077, a critical (CVSS 9.8) deserialization flaw in JetBrains TeamCity allowing unauthenticated remote code execution, to its Known Exploited Vulnerabilities catalog on August 5, 2026, with a federal remediation deadline of August 8.

What Is It

CVE-2026-63077 is a deserialization of untrusted data vulnerability (CWE-502) in JetBrains TeamCity. Per the NVD record, unauthenticated remote code execution was possible via the agent polling protocol. The CVE was published July 27, 2026, and is now in "Analyzed" status.

JetBrains scored it CVSS 3.1 base 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, with high confidentiality, integrity, and availability impact.

Why It Matters

CISA's KEV listing confirms active exploitation: the SSVC decision data records exploitation as active, automatable as yes, and technical impact as total. The three-day remediation window, added August 5, due August 8, is unusually short and signals urgency.

Known ransomware campaign use is listed as Unknown in the KEV entry.

What's Vulnerable

Per the NVD configuration data:

Fixed versions are 2026.1.3 and 2025.11.7.

Patch Status

CISA's required action: apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 "Prioritizing Security Updates Based on Risk" guidance and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Due date for federal civilian agencies: August 8, 2026.

Sources