CVE-2026-63077: Critical Unauth RCE in JetBrains TeamCity via Deserialization of Untrusted Data

Last Updated: Monday, August 10, 2026 9:02 PM

What’s Happening

CVSSv3: 9.8

On July 27th, 2026 Jetsbrains released a security advisory for an unauthenticated RCE via Deserializaton of Untrusted Data in their TeamCity CI/CD tool. On August 5th, it was added to CISA’s KEV list. There is an update available as well as an alternative security patch.

The JetBrains Advisory:

Rapid7’s Analysis:

Rapid7’s POC:

Actions

Update to the latest version of JetBrains TeamCity if capable. Otherwise implement JetBrains’ security patch, which can be found in their security advisory. It is also a good idea to not expose TeamCity servers to the public internet.

Notes

The CVE record:

https://www.cve.org/CVERecord?id=CVE-2026-63077

1 Like