What is CVE-2026-63077?
CVE-2026-63077 is a critical unsafe deserialization vulnerability in JetBrains TeamCity. An attacker can achieve unauthenticated remote code execution (RCE) by exploiting the agent polling protocol over HTTP/HTTPS without credentials. Immediate patching is strongly advised.
Azərbaycanca: CVE-2026-63077, JetBrains TeamCity-də aşkarlanmış kritik "unsafe deserialization" zəifliyidir. Bu, HTTP/HTTPS üzərindən autentifikasiya olmadan agent sorğu protokolunu istismar edərək serverdə uzaqdan kod icrasına (RCE) imkan verir. Təsirə məruz qalan sistemlərin dərhal yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which product is affected by CVE-2026-63077?
This vulnerability affects JetBrains TeamCity.
Is authentication required to exploit CVE-2026-63077?
No, this vulnerability allows unauthenticated remote code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.