# JetBrains TeamCity remote code execution vulnerability

> Live situation record from CLSTR: https://clstr.news/situations/jetbrains-teamcity-remote-code-execution-vulnerability
> Updated: 2026-08-25T00:05:51.000Z. Sources: 5. Developments: 2.

On July 27, 2026, JetBrains disclosed a critical unauthenticated remote code execution vulnerability, identified as CVE-2026-63077, affecting all versions of TeamCity On-Premises. The flaw, which carries a CVSS score of 9.8, involves a deserialization issue in the agent polling protocol. If exploited, an attacker with HTTP(S) access could bypass authentication to execute arbitrary operating-system commands, potentially compromising CI/CD pipelines and reading stored credentials. At the time of disclosure, JetBrains reported no evidence of active exploitation.

By late August, the Australian Cyber Security Centre (ACSC) issued a high-severity alert indicating that the vulnerability was being actively exploited within Australia. The ACSC warned that the flaw poses significant risks to the integrity of build artifacts and the exposure of sensitive configurations. The agency advised organizations to apply patches immediately and monitor for suspicious activity.

## Timeline

### 2026-08-25: Australian Cyber Security Centre warns of active TeamCity server exploitation

The ACSC has warned of active exploitation of a critical 9.8-rated vulnerability (CVE-2026-63077) in JetBrains' TeamCity On-Premises servers affecting organisations in Australia.

5 sources. https://clstr.news/cluster/australian-cyber-security-centre-warns-of-active-teamcity-server-exploitation

### 2026-07-29: JetBrains releases patches for critical TeamCity On-Premises remote code execution flaw

JetBrains disclosed CVE-2026-63077, a critical unauthenticated RCE bug in TeamCity On-Premises, and urged users to upgrade to 2025.11.7/2026.1.3 or apply a patch; cloud instances are unaffected.

2 sources. https://clstr.news/cluster/jetbrains-releases-patches-for-critical-teamcity-on-premises-remote-code-execution-flaw

---
Cite as: JetBrains TeamCity remote code execution vulnerability. CLSTR, https://clstr.news/situations/jetbrains-teamcity-remote-code-execution-vulnerability
