importantSYS.SOURCE: The Hacker News• 2026-08-06T12:21:43+05:30
CISA Warns of Active Exploitation of TeamCity RCE Vulnerability CVE-2026-63077
CISA has identified the TeamCity CVE-2026-63077 vulnerability, a critical remote code execution (RCE) flaw exploiting deserialization of untrusted data, currently under active exploitation. Federal agencies are urged to apply patches by August 8, 2026, per BOD 26-04 requirements.
A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a case of deserialization of untrusted data that could allow an unauthenticated attacker with access to a TeamCity server
*** END OF TRANSMISSION ***