CVE-2026-63077 (CVSS score: 9.8) is a deserialization vulnerability in on‑premise JetBrains TeamCity that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) says is being actively exploited in the wild.
CVE-2026-63077 and the agent polling protocol
CISA and JetBrains describe CVE-2026-63077 as a case of "deserialization of untrusted data" that can be reached via the TeamCity agent polling protocol. CISA warned that the flaw "could allow unauthenticated remote code execution via the agent polling protocol," and JetBrains similarly noted that an "unauthenticated attacker" exploiting the vulnerability can sidestep authentication checks and execute arbitrary operating system commands on the server running TeamCity.
How exploitation translates to system control
Successful exploitation depends on the privileges granted to the TeamCity server process. Because the exploit executes operating system commands with the TeamCity server process’s privileges, attackers could extract TeamCity data and configurations, retrieve stored credentials, or modify server state. JetBrains explicitly warns the flaw can "expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleCISA’s alert, JetBrains’ posture, and outstanding unknowns
CISA has flagged the issue and indicated it is under active exploitation. At the same time, the specifics remain limited: according to the advisory material, "It's currently not known how the vulnerability is being exploited in the wild, the identity of the threat actors behind the attacks, and the scale of such efforts." The reporting also notes that JetBrains has not yet updated its advisory to confirm active exploitation.
BOD 26-04, the KEV catalog, and the August 8 federal deadline
The advisory links the incident to federal operational requirements. Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies must prioritize patching high‑risk vulnerabilities that appear in the Known Exploited Vulnerabilities (KEV) catalog. For CVE-2026-63077, the deadline by which federal agencies must apply software patches or mitigations is August 8, 2026.
What this means for on-premise TeamCity users, FCEB agencies, and CI/CD managers
- On-premise TeamCity users: The source recommends that users running on‑premise versions "apply the updates as soon as possible." Given the vulnerability allows unauthenticated remote code execution via the agent polling protocol, on‑premise administrators are the immediate audience for the available patches.
- Federal Civilian Executive Branch agencies: BOD 26-04 requires agencies to prioritize high‑risk KEV entries; the advisory sets an explicit compliance deadline of August 8, 2026, for agencies to apply patches or mitigations for CVE-2026-63077.
- CI/CD managers and build‑artifact owners: JetBrains’ advisory stresses that successful exploitation can "potentially compromise the integrity of build artifacts and downstream CI/CD pipelines," placing continuous integration and deployment pipelines that rely on TeamCity into a risk category for review and remediation.
The public record assembled in the advisory is precise about the mechanics and consequences of CVE-2026-63077, and clear about one immediate operational step: apply the available patches without delay. It is equally clear that questions remain — notably how attackers are exploiting the flaw, which actors are responsible, and how widespread the exploitation has become — and that JetBrains has not yet updated its advisory to confirm active exploitation. For organizations that host TeamCity on‑premise, and for the federal agencies bound by BOD 26‑04, the window to act is short: August 8, 2026.




