In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
PoC: CVE-2026-63077
Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
[POC] GHSA-3whf-vgf2-9w6g — teamcity-cve-2026-63077-remediation
JetBrains TeamCity On-Premises CVE-2026-63077 Emergency Hardening & Patch Runbook Package
PoC: CVE-2026-63077
CVE-2026-63077 — Unauthenticated Remote Code Execution in JetBrains TeamCity via agent polling protocol deserialization. CVSS 9.8 CRITICAL. Mass exploitation tool with interactive shell, multi-threading, and real-time result logging.
PoC: teamcity-CVE-2026-63077-pcap
teamcity teamcity-CVE-2026-63077 exploitation pcap
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free