Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4238 articles · 221926 vulns · 36/41 feeds (7d)
← Back to list
9.8
CVE-2026-63077KEVEXPLOITEDPATCHED
jetbrains · teamcity

CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin

Description

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Affected Products

VendorProductVersions
jetbrainsteamcity0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
jetbrainsteamcitycert_advisory90%

References

  • https://www.jetbrains.com/privacy-security/issues-fixed/

Related News (14 articles)

Tier D
BleepingComputer1h ago
CISA: Ransomware gangs now exploiting critical TeamCity flaw
→ No new info (linked only)
Tier D
The Hacker News18d ago
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
→ No new info (linked only)
Tier B
CERT-FR45d ago
Bulletin d'actualité CERTFR-2026-ACT-034 (10 août 2026)
→ No new info (linked only)
Tier C
Rapid7 Blog47d ago
Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
→ No new info (linked only)
Tier D
The Hacker News49d ago
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
→ No new info (linked only)
Tier D
CSO Online55d ago
JetBrains says a crafted HTTP request could break TeamCity
→ No new info (linked only)
Tier D
SecurityWeek55d ago
Critical Code Execution Vulnerability Patched in TeamCity 
→ No new info (linked only)
Tier D
BleepingComputer55d ago
JetBrains warns of critical TeamCity remote code execution flaw
→ No new info (linked only)
Tier C
Rapid7 Blog56d ago
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
→ No new info (linked only)
Tier D
Heise Security57d ago
Kritische Schwachstelle in JetBrains TeamCity entdeckt
→ No new info (linked only)
Tier D
Help Net Security58d ago
JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
→ No new info (linked only)
Tier B
BSI Advisories58d ago
[NEU] [hoch] JetBrains TeamCity: Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
Tier D
The Hacker News58d ago
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
→ No new info (linked only)
Tier C
VulDB58d ago
CVE-2026-63077 | JetBrains TeamCity prior 2026.1.3/2025.11.7 Agent Polling Protocol code injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
2026.1.32025.11.7
CWECWE-502
PublishedJul 27, 2026
Last enriched58d ago
Trending Score169🔥
Source articles14
Independent10
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-86478
CVE-2026-86478: In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthent
Trending: 10
HIGHCVE-2026-86502
CVE-2026-86502: In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code ex
Trending: 7
CRITICALCVE-2026-86480
CVE-2026-86480: In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser pri
Trending: 7
HIGHCVE-2026-86479
CVE-2026-86479: In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restric
Trending: 7
HIGHCVE-2026-86482
CVE-2026-86482: In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation
Trending: 7

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 27, 2026
Added to CISA KEV
Jul 27, 2026
Discovered by ZDM
Jul 27, 2026
Actively Exploited
Sep 23, 2026
Exploit Available
Sep 23, 2026
Patch Available
Sep 23, 2026