CISA Adds JetBrains TeamCity RCE Flaw (CVE-2026-63077) to KEV Catalog Due to Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution (RCE) vulnerability in JetBrains TeamCity, tracked as CVE-2026-63077 (CVSS score: 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. This deserialization of untrusted data flaw allows an unauthenticated attacker with access to a TeamCity server to bypass authentication and execute arbitrary operating system commands. Federal Civilian Executive Branch (FCEB) agencies are advised to apply fixes by August 6, 2026, due to active exploitation in the wild.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai