Attackers Exploit Patched JetBrains TeamCity RCE
Attackers are actively exploiting CVE-2026-63077, a critical deserialization flaw in TeamCity On-Premises that enables unauthenticated remote code execution. JetBrains has published patches.
Attackers have begun exploiting a recently patched vulnerability in JetBrains TeamCity tracked as CVE-2026-63077. The flaw has a CVSS score of 9.8 and affects TeamCity On-Premises installations. JetBrains released fixes in versions 2025.11.7 and 2026.1.3 and published a security patch plugin covering older releases back to 2017.1+.
The defect is a deserialization-of-untrusted-data vulnerability reachable via HTTP/S requests and the TeamCity agent polling protocol. JetBrains warned the flaw allows an unauthenticated actor to bypass authentication checks and run arbitrary operating system commands with the privileges of the TeamCity server process. Build servers commonly have access to source code, build artifacts and deployment credentials, so a successful exploit can expose those assets and systems the server interacts with.
JetBrains reported the issue privately and stated it was not aware of active exploitation at the time of public disclosure. Days later, the U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog and directed federal agencies to apply patches within three days under Binding Operational Directive 26-04.
There is no public technical analysis of the attacks or confirmed information about targeted organizations beyond the federal advisory listing. Administrators running TeamCity On-Premises should apply the vendor updates or install the security plugin for legacy versions immediately. Organizations unable to patch right away can reduce exposure by isolating TeamCity servers from untrusted networks, restricting access to agent polling endpoints, and monitoring logs for unusual HTTP/S requests or unexpected process activity.
If compromise is suspected, perform a forensic review of the build server and any systems it communicates with. Security teams should track JetBrains advisories and follow CISA guidance for KEV-listed vulnerabilities.








