A critical security flaw has been identified in JetBrains TeamCity that requires immediate attention from system administrators and IT teams managing development infrastructure. Designated as CVE-2026-63077, this issue involves a deserialization of untrusted data vulnerability.

Because this vulnerability carries a high severity score of 9.8, organizations utilizing the affected software need to understand the potential risks and take prompt action to secure their environments. Notably, this issue is currently tracked on CISA's Known Exploited Vulnerabilities list, meaning active exploitation attempts have been observed in the wild.

What Happened

The vulnerability exists within JetBrains TeamCity. Specifically, it features a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. This means an unauthorized actor could potentially interact with the vulnerable service remotely without needing prior credentials, leveraging the agent polling mechanism to execute arbitrary code.

Who Should Care

Site owners, system administrators, and small-to-medium businesses utilizing JetBrains TeamCity in their software development pipelines must prioritize this advisory. If your organization hosts a TeamCity server that is accessible via the network or the internet, your infrastructure could be exposed to potential compromise.

What to Do Now

Addressing high-severity vulnerabilities promptly is a core part of maintaining a secure technical posture. To protect your systems from CVE-2026-63077, consider taking the following steps:

  • Review your inventory: Verify whether your organization runs JetBrains TeamCity and identify all instances deployed across your network.
  • Consult official advisories: Visit the Korisec CVE tracker page for detailed tracking information.
  • Apply vendor guidance: Check with JetBrains directly for official patches, updates, or configuration workarounds to mitigate the remote code execution risk.
  • Restrict network access: Limit exposure by ensuring that management interfaces and agent polling ports are not unnecessarily exposed to the public internet.

Maintaining visibility into your external attack surface helps ensure that known flaws are addressed before they can be leveraged against your infrastructure.

Ready to check your external security posture? Run a free check today.