← back

CVE-2026-63077

CRITICAL · 9.8 EPSS 0.6%
hype MIXED · 62 hack

Real critical vuln, patches live, but no KEV, no PoC signal, chatter mostly recycled concern.

What: JetBrains TeamCity unauthenticated remote code execution via the agent polling protocol (CVSS 9.8 CRITICAL). Affects versions before 2026.1.3 and 2025.11.7.

Why it matters: CRITICAL severity and zero authentication requirement make this high-impact for CI/CD infrastructure. Published 2026-07-27; patches already available. Not yet KEV-listed but EPSS 0.47% reflects low current exploitation prevalence. Social chatter emphasizes urgency and patch applicability.

Where it's seen: Blog posts and social media amplifying urgency ("Patch Now"), vendor advisory coverage, debate around patch completeness and prior exploitation gaps. No PoC public in supplied posts; chatter is alarm-driven rather than proof-driven.

RISK: CRITICAL — Unauthenticated RCE in CI/CD backbone, CVSS 9.8, patches available.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 7/29/2026, 5:43:08 AM

Description

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CVSS 3.1 breakdown

Exploitability 3.9 · Impact 5.9
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Weaknesses