Wire · technology
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 30 August 2026 · Fusion42 review
CISA has flagged a critical remote code execution vulnerability (CVE-2026-63077) in on-premise JetBrains TeamCity servers that is actively being exploited in the wild. The flaw allows unauthenticated attackers to bypass authentication via the agent polling protocol and execute arbitrary OS commands with server privileges.
This Wire brief sits within Fusion42's coverage of Enterprise Software, and 3 sources have reported it between 28 Jul 2026 and 6 Aug 2026.
◆ ◆ The Wire takeaway
Your on-premise software infrastructure just became a clear target if it uses TeamCity. Patch or isolate these servers now to avoid becoming a breach entry point.
◆ Coverage
3 sources · first reported 28 Jul 2026 · latest 6 Aug 2026
◆ Related on Wire
◆ Topics