Our automated tracking framework flagged that CISA added CVE-2026-63077 (JetBrains TeamCity) to the Known Exploited Vulnerabilities (KEV) catalog on August 8, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.

What CISA Reported

CISA describes the flaw as follows: “JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.”

Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-63077 by August 8, 2026 — a 3-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.

The Details

CVE CVE-2026-63077
Vendor / product JetBrains TeamCity
Vulnerability JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
CVSS base score 9.8
Added to KEV August 5, 2026
Days public before listing (NVD → KEV lag) 9
Federal patch deadline August 8, 2026
Known ransomware use No

How This Compares

This is one of the first CISA KEV entries we have tracked for JetBrains, so there is not yet a vendor-specific median. For context, here is the whole catalog:

Across all tracked KEV entries Value
Entries with verified publication dates 1662
Median lag (disclosure → KEV listing) 271 days
Exploited within 7 days of disclosure 23%
Tied to known ransomware campaigns 20%

Full context is on our KEV Lag Tracker.

Other Recent JetBrains KEV Additions

The most recent JetBrains vulnerabilities CISA has confirmed as actively exploited, from our tracker:

CVE Product Added to KEV Lag (days) Ransomware
CVE-2024-27199 TeamCity April 20, 2026 777 ⚠️ Yes
CVE-2024-27198 TeamCity March 7, 2024 3 ⚠️ Yes
CVE-2023-42793 TeamCity October 4, 2023 15 ⚠️ Yes

What This Means for Defenders

CISA has added CVE-2026-63077, a critical deserialization of untrusted data vulnerability in JetBrains TeamCity, to its Known Exploited Vulnerabilities (KEV) catalog. With a CVSS base score of 9.8, this flaw presents an urgent risk, particularly for organizations using TeamCity in internet-facing environments or as part of critical build and deployment pipelines. Federal agencies face a tight deadline of August 8, 2026, to patch, underscoring the immediate need for all organizations to prioritize remediation.

The vulnerability was publicly known for 9 days before its inclusion in the KEV catalog, indicating active exploitation began very soon after public disclosure. This short NVD-to-KEV lag, combined with JetBrains’ historical median lag of 12 days for KEV entries, suggests a rapid weaponization cycle. While no known ransomware use has been reported for this specific CVE, the severity and exploitability mean threat actors are likely leveraging it for initial access or privilege escalation.

Security teams should immediately identify all TeamCity instances and apply the necessary patches. If immediate patching isn’t feasible before the August 8 deadline, organizations must implement strong compensating controls. This includes isolating TeamCity instances, restricting network access to only essential services, implementing network intrusion detection/prevention systems to monitor for exploitation attempts, and enhancing logging to detect suspicious activity. Due to the high severity and confirmed exploitation, assume compromise until proven otherwise if patching is delayed.

Related Coverage

How We Track This

This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.