CVEFinder.io

CVE-2026-63077

β›” critical
πŸ” Scan for this CVE
Summary

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CVSS Score
9.8
Critical
EPSS Score
10.7
Exploit Probability
Published Date
2026-07-27
First Seen: 2026-07-31
πŸ“Š Relative Risk Intelligence

This CVE is Very High Risk - more severe than 90.5% of all 345,139 vulnerabilities in our database.

#32,849
Top 10% most severe
Severity Percentile
🎯 CISA SSVC Assessment Updated: Jul 27, 2026
πŸ” Exploitation Status
Active
Exploits detected in the wild
βš™οΈ Automatable
YES
Can be exploited automatically
πŸ’₯ Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2026-08-06
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE IDs (Weakness Types)

πŸ“¦ Affected Products 2

πŸ”— References 2

πŸ”— Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-65906 ⚠️ high 8.8 0.4 In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible 2026-07-23
CVE-2026-59793 ⚠️ high 8.8 0.3 In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration 2026-07-10
CVE-2026-59794 ⚠️ high 7.3 0.2 In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data 2026-07-10
CVE-2026-59795 ⚠️ high 8.1 0.2 In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible 2026-07-10
CVE-2026-59796 ⚠️ high 8.1 0.3 In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks 2026-07-10
CVE-2026-49371 ⚠️ high 7.1 0.3 In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible 2026-05-29
These CVEs affect the same products