cbcvebase.
CVE-2026-63077
published 2026-07-27

CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-08-08
Exploited in the wild
EPSS
87.71%
99.8th percentile
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Affected

3 ranges
VendorProductVersion rangeFixed in
jetbrainsteamcity< 2026.1.3, 2025.11.72026.1.3, 2025.11.7
jetbrainsteamcity< 2025.11.72025.11.7
jetbrainsteamcity>= 2026.1 < 2026.1.32026.1.3

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.