CVE-2026-63077: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Other sources
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains TeamCityto a version that resolves this vulnerability.Fixed in 2026.1.3 - Upgrade
Upgrade
JetBrains TeamCityto a version that resolves this vulnerability.Fixed in 2025.11.7 - Compensating control
Evaluate each asset for internet exposure and apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”.
- Compensating control
If mitigations are unavailable for this issue, discontinue use of JetBrains TeamCity (per BOD 26-04 guidance for cloud services or discontinue use of the product).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63077?
The severity of CVE-2026-63077 is critical with a CVSS score of 9.8.
How do I fix CVE-2026-63077?
To fix CVE-2026-63077, upgrade JetBrains TeamCity to version 2026.1.3 or 2025.11.7 or later.
What type of vulnerability is CVE-2026-63077?
CVE-2026-63077 is an unauthenticated remote code execution vulnerability.
Which versions of JetBrains TeamCity are affected by CVE-2026-63077?
Versions of JetBrains TeamCity prior to 2026.1.3 and 2025.11.7 are affected by CVE-2026-63077.
What protocols are involved in CVE-2026-63077?
CVE-2026-63077 involves the agent polling protocol in JetBrains TeamCity.