CVE-2026-63077

CRITICAL KEV NUCLEI

Jetbrains TeamCity < 2026.1.3, 2025.11.7 - Deserialization of Untrusted Data

Title source: rule
STIX 2.1

Exploitation Summary

CVE-2026-63077 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 5, 2026. EIP tracks 4 public exploits from researchers including AnggaTechI, BoredHackerBlog, sfewer-r7. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2026-63077, an unauthenticated remote code execution vulnerability in JetBrains TeamCity via deserialization of untrusted data in the agent polling protocol. The exploit leverages HSQLDB scripting to write a JSP webshell to the web root and execute arbitrary commands.

Description

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Exploits (4)

nomisec WORKING POC
by AnggaTechI · remote
https://github.com/AnggaTechI/CVE-2026-63077

This repository contains a functional proof-of-concept exploit for CVE-2026-63077, an unauthenticated remote code execution vulnerability in JetBrains TeamCity via deserialization of untrusted data in the agent polling protocol. The exploit leverages HSQLDB scripting to write a JSP webshell to the web root and execute arbitrary commands.

Classification
Working Poc 98%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: JetBrains TeamCity On-Premises (versions before 2025.11.7 and 2026.1.3)
No auth needed
Prerequisites: Target must be running a vulnerable version of TeamCity On-Premises · Bash must be available on the target server (for command execution) · HTTP/HTTPS access to the TeamCity server
mistral-large-3 · analyzed Aug 08, 2026 Full analysis →
nomisec WRITEUP
by BoredHackerBlog · remote
https://github.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap

This repository contains a PCAP file demonstrating the exploitation of CVE-2026-63077, an unauthenticated RCE vulnerability in JetBrains TeamCity. The PCAP captures the HTTP requests used to trigger a deserialization flaw via HSQLDB metadata storage, leading to arbitrary code execution through crafted SQL commands in connection initialization scripts.

Classification
Writeup 95%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: JetBrains TeamCity 2025.11.3
No auth needed
Prerequisites: Network access to TeamCity server (port 8111) · Target running vulnerable version (2025.11.3)
mistral-large-3 · analyzed Aug 08, 2026 Full analysis →
github WORKING POC
by sfewer-r7 · pythonremote
https://github.com/sfewer-r7/CVE-2026-63077

This exploit leverages an unauthenticated XStream deserialization vulnerability (CVE-2026-63077) in JetBrains TeamCity to achieve remote code execution. The PoC constructs a gadget chain that writes a polyglot SQL/JSP file to disk, then executes arbitrary commands via a one-shot JSP terminal.

Classification
Working Poc 99%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: JetBrains TeamCity (versions vulnerable to CVE-2026-63077)
No auth needed
Prerequisites: Target must be running a vulnerable version of TeamCity · Network access to the TeamCity server · Knowledge of the webroot relative path (configurable)
mistral-large-3 · analyzed Aug 07, 2026 Full analysis →
github WRITEUP
by unveiledhistory49 · pythonpoc
https://github.com/unveiledhistory49/teamcity-cve-2026-63077-remediation

This repository provides comprehensive remediation and forensic analysis tooling for CVE-2026-63077, an unauthenticated RCE vulnerability in JetBrains TeamCity's agent polling protocol. It includes scripts for log analysis, process inspection, patch verification, and post-exploitation forensics, but does not contain exploit code.

Classification
Writeup 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: JetBrains TeamCity (versions prior to 2023.11.5 and 2024.03.2)
No auth needed
Prerequisites: Access to TeamCity server logs and filesystem · Privileges to inspect running processes and system configurations
mistral-large-3 · analyzed Jul 31, 2026 Full analysis →

Nuclei Templates (1)

JetBrains TeamCity < 2026.1.3, 2025.11.7 - Remote Code Execution
CRITICALVERIFIEDby 0x_Akoko,pdteam
Shodan: title:"TeamCity"
FOFA: title="TeamCity"

Scores

CVSS v3 9.8
EPSS 0.1072
EPSS Percentile 95.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-08-05
VulnCheck KEV 2026-08-05
ENISA EUVD EUVD-2026-49369
CWE
CWE-502
Status published
Products (2)
jetbrains/teamcity < 2025.11.7
JetBrains/TeamCity < 2026.1.3, 2025.11.7
Published Jul 27, 2026
KEV Added Aug 05, 2026
Tracked Since Jul 27, 2026