CVE-2026-63077: Critical severity JetBrains TeamCity vulnerability
Published Jul 27, 2026
·Updated
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Affected Software
2 affected components
JetBrains TeamCity<2026.1.3
JetBrains TeamCity<2025.11.7
Event History
Jul 27, 2026
CVE Published
via MITRE·04:44 PM
Data Sourced
via MITRE·04:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-63077?
The severity of CVE-2026-63077 is critical with a CVSS score of 9.8.
2
How do I fix CVE-2026-63077?
To fix CVE-2026-63077, upgrade JetBrains TeamCity to version 2026.1.3 or 2025.11.7 or later.
3
What type of vulnerability is CVE-2026-63077?
CVE-2026-63077 is an unauthenticated remote code execution vulnerability.
4
Which versions of JetBrains TeamCity are affected by CVE-2026-63077?
Versions of JetBrains TeamCity prior to 2026.1.3 and 2025.11.7 are affected by CVE-2026-63077.
5
What protocols are involved in CVE-2026-63077?
CVE-2026-63077 involves the agent polling protocol in JetBrains TeamCity.