Skip to main content

Social ABC Bookmarking Website | Do Follow 2025

CVE-2026-63077: How a TeamCity Deserialization Flaw Opens the Door to RCE

CVE-2026-63077 is a critical deserialization of untrusted data vulnerability in JetBrains TeamCity On-Premises. An unauthenticated attacker with HTTP(S) access to a vulnerable TeamCity server can abuse the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.

Successful exploitation can expose TeamCity data, configurations, and stored credentials. It can also allow changes to server state and potentially compromise build artifacts and downstream CI/CD pipelines. The vulnerability affects TeamCity versions before 2025.11.7 and 2026.1.3. CISA added the vulnerability to its KEV catalog on August 5, 2026, after exploitation was observed in the wild.