Last Updated: Monday, August 10, 2026 9:02 PM
What’s Happening
CVSSv3: 9.8
On July 27th, 2026 Jetsbrains released a security advisory for an unauthenticated RCE via Deserializaton of Untrusted Data in their TeamCity CI/CD tool. On August 5th, it was added to CISA’s KEV list. There is an update available as well as an alternative security patch.
The JetBrains Advisory:
Rapid7’s Analysis:
Rapid7’s POC:
Actions
Update to the latest version of JetBrains TeamCity if capable. Otherwise implement JetBrains’ security patch, which can be found in their security advisory. It is also a good idea to not expose TeamCity servers to the public internet.
Notes
The CVE record: