CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
What happened
CISA has flagged a critical deserialization vulnerability in on-premise JetBrains TeamCity servers (CVE-2026-63077) as being actively exploited. The flaw allows unauthenticated attackers to achieve remote code execution with a CVSS score of 9.8.
Why it ranks #1
Confirmed active exploitation of a critical RCE in enterprise infrastructure takes top priority under the rubric.
Who should care
IT and platform operations, SOC and incident response teams
What to do
Apply the latest JetBrains TeamCity security patches immediately.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- disclosed