Our automated tracking framework flagged that CISA added CVE-2026-63077 (JetBrains TeamCity) to the Known Exploited Vulnerabilities (KEV) catalog on August 8, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.
What CISA Reported
CISA describes the flaw as follows: “JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.”
Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-63077 by August 8, 2026 — a 3-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.
The Details
| CVE | CVE-2026-63077 |
| Vendor / product | JetBrains TeamCity |
| Vulnerability | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability |
| CVSS base score | 9.8 |
| Added to KEV | August 5, 2026 |
| Days public before listing (NVD → KEV lag) | 9 |
| Federal patch deadline | August 8, 2026 |
| Known ransomware use | No |
How This Compares
This is one of the first CISA KEV entries we have tracked for JetBrains, so there is not yet a vendor-specific median. For context, here is the whole catalog:
| Across all tracked KEV entries | Value |
|---|---|
| Entries with verified publication dates | 1662 |
| Median lag (disclosure → KEV listing) | 271 days |
| Exploited within 7 days of disclosure | 23% |
| Tied to known ransomware campaigns | 20% |
Full context is on our KEV Lag Tracker.
Other Recent JetBrains KEV Additions
The most recent JetBrains vulnerabilities CISA has confirmed as actively exploited, from our tracker:
| CVE | Product | Added to KEV | Lag (days) | Ransomware |
|---|---|---|---|---|
| CVE-2024-27199 | TeamCity | April 20, 2026 | 777 | ⚠️ Yes |
| CVE-2024-27198 | TeamCity | March 7, 2024 | 3 | ⚠️ Yes |
| CVE-2023-42793 | TeamCity | October 4, 2023 | 15 | ⚠️ Yes |
What This Means for Defenders
CISA has added CVE-2026-63077, a critical deserialization of untrusted data vulnerability in JetBrains TeamCity, to its Known Exploited Vulnerabilities (KEV) catalog. With a CVSS base score of 9.8, this flaw presents an urgent risk, particularly for organizations using TeamCity in internet-facing environments or as part of critical build and deployment pipelines. Federal agencies face a tight deadline of August 8, 2026, to patch, underscoring the immediate need for all organizations to prioritize remediation.
The vulnerability was publicly known for 9 days before its inclusion in the KEV catalog, indicating active exploitation began very soon after public disclosure. This short NVD-to-KEV lag, combined with JetBrains’ historical median lag of 12 days for KEV entries, suggests a rapid weaponization cycle. While no known ransomware use has been reported for this specific CVE, the severity and exploitability mean threat actors are likely leveraging it for initial access or privilege escalation.
Security teams should immediately identify all TeamCity instances and apply the necessary patches. If immediate patching isn’t feasible before the August 8 deadline, organizations must implement strong compensating controls. This includes isolating TeamCity instances, restricting network access to only essential services, implementing network intrusion detection/prevention systems to monitor for exploitation attempts, and enhancing logging to detect suspicious activity. Due to the high severity and confirmed exploitation, assume compromise until proven otherwise if patching is delayed.
Related Coverage
- Critical IBM Langflow Flaw CVE-2026-9198 (CVSS 9.8) Added to CISA KEV (August 2026)
- Cisco’s CVE-2026-20316 Was Exploited in 0 Days — Well Under Its 1245-Day Median (July 2026)
How We Track This
This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.