What is CVE-2026-63077?
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Timeline
- 2026-07-27Published to the U.S. National Vulnerability Database (NVD)
- 2026-07-28NVD record last updated
Affected product
See advisory
Remediation Steps
- Update TeamCity on-premises instances to version 2025.11.7 or 2026.1.3 or later
- Restrict network access to TeamCity management interfaces to authorized administrators only
- Review TeamCity audit logs for unauthorized command execution attempts
- Verify that TeamCity Cloud instances are running patched versions
- Test patch deployment in non-production environment before production rollout
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 4 of July 2026 (July 27 – August 2)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.