securityonline.info
CVE-2026-63077: TeamCity RCE Flaw Exploited in the Wild, CISA Warns
TL;DR CISA added the TeamCity vulnerability CVE-2026-63077 to its Known Exploited Vulnerabilities catalog. The flaw allows unauthenticated remote code execution on TeamCity On-Premises servers. Federal agencies must patch by August 8, 2026. Why This TeamCity Vulnerability Matters TeamCity runs build pipelines for thousands of software teams. Therefore, a server compromise can poison downstream code. A successful attack can expose stored credentials, alter server state, and taint build artifacts.