CISA adds JetBrains TeamCity deserialization RCE to KEV — three-day patch deadline
CISA added CVE-2026-63077 to the Known Exploited Vulnerabilities catalog today: an unauthenticated deserialization bug in TeamCity's agent-polling protocol that leads to remote code execution, with a due date of August 8. TeamCity servers are CI/CD crown jewels — build credentials, source access, and deploy keys all sit behind this endpoint — and KEV's three-day window signals CISA has direct evidence of in-the-wild exploitation, not just theoretical risk. Patch internet-facing TeamCity servers now; if you can't patch immediately, pull the server offline or firewall the agent-polling port until you can.