CVE-2026-63077
CRITICAL KEV NUCLEIJetbrains TeamCity < 2026.1.3, 2025.11.7 - Deserialization of Untrusted Data
Title source: ruleExploitation Summary
CVE-2026-63077 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 5, 2026. EIP tracks 4 public exploits from researchers including AnggaTechI, BoredHackerBlog, sfewer-r7. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2026-63077, an unauthenticated remote code execution vulnerability in JetBrains TeamCity via deserialization of untrusted data in the agent polling protocol. The exploit leverages HSQLDB scripting to write a JSP webshell to the web root and execute arbitrary commands.
Description
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Exploits (4)
This repository contains a functional proof-of-concept exploit for CVE-2026-63077, an unauthenticated remote code execution vulnerability in JetBrains TeamCity via deserialization of untrusted data in the agent polling protocol. The exploit leverages HSQLDB scripting to write a JSP webshell to the web root and execute arbitrary commands.
This repository contains a PCAP file demonstrating the exploitation of CVE-2026-63077, an unauthenticated RCE vulnerability in JetBrains TeamCity. The PCAP captures the HTTP requests used to trigger a deserialization flaw via HSQLDB metadata storage, leading to arbitrary code execution through crafted SQL commands in connection initialization scripts.
This exploit leverages an unauthenticated XStream deserialization vulnerability (CVE-2026-63077) in JetBrains TeamCity to achieve remote code execution. The PoC constructs a gadget chain that writes a polyglot SQL/JSP file to disk, then executes arbitrary commands via a one-shot JSP terminal.
This repository provides comprehensive remediation and forensic analysis tooling for CVE-2026-63077, an unauthenticated RCE vulnerability in JetBrains TeamCity's agent polling protocol. It includes scripts for log analysis, process inspection, patch verification, and post-exploitation forensics, but does not contain exploit code.
Nuclei Templates (1)
title:"TeamCity"
title="TeamCity"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H