CRITICAL
CVE-2026-63077
CVSS
9.8
KEV
Description
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Summary dbcve.org
A critical unauthenticated remote code execution vulnerability exists in JetBrains TeamCity's agent polling protocol. Attackers can execute arbitrary code on the TeamCity server without any authentication by sending specially crafted requests through the agent communication channel, which lacks proper input validation.
Mitigation
Immediately upgrade TeamCity to version 2026.1.3 or 2025.11.7 or later. If immediate upgrade is not possible, consider blocking external access to the agent polling endpoints at the network perimeter while planning the upgrade.
Weakness (CWE)
CWE-502
Deserialization of Untrusted Data
EPSS Score
86.52%
Probability of exploitation in next 30 days
99.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.