Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3357 articles · 182803 vulns · 36/41 feeds (7d)
← Back to list
9.8
CVE-2026-63077PATCHED
JetBrains · TeamCity

CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin

Description

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Affected Products

VendorProductVersions
JetBrainsTeamCity0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
jetbrainsteamcitycert_advisory90%

References

  • https://www.jetbrains.com/privacy-security/issues-fixed/

Related News (9 articles)

Tier D
CSO Online5h ago
JetBrains says a crafted HTTP request could break TeamCity
→ No new info (linked only)
Tier D
SecurityWeek9h ago
Critical Code Execution Vulnerability Patched in TeamCity 
→ No new info (linked only)
Tier D
BleepingComputer18h ago
JetBrains warns of critical TeamCity remote code execution flaw
→ No new info (linked only)
Tier C
Rapid7 Blog2d ago
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
→ No new info (linked only)
Tier D
Heise Security2d ago
Kritische Schwachstelle in JetBrains TeamCity entdeckt
→ No new info (linked only)
Tier D
Help Net Security3d ago
JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
→ No new info (linked only)
Tier B
BSI Advisories3d ago
[NEU] [hoch] JetBrains TeamCity: Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
Tier D
The Hacker News3d ago
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-63077 | JetBrains TeamCity prior 2026.1.3/2025.11.7 Agent Polling Protocol code injection
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.1.32025.11.7
CWECWE-502
PublishedJul 27, 2026
Last enriched3d ago
Trending Score80
Source articles9
Independent9
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-64812
CVE-2026-64812: In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
Trending: 24
CRITICALCVE-2026-64813
CVE-2026-64813: In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
Trending: 24
HIGHCVE-2026-64814
CVE-2026-64814: In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
Trending: 20
CRITICALCVE-2026-65907
CVE-2026-65907: In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
Trending: 19
HIGHCVE-2026-64807
CVE-2026-64807: In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
Trending: 17

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 27, 2026
Discovered by ZDM
Jul 27, 2026
Patch Available
Jul 28, 2026