tag
Agent-Polling
CVE-2026-63077
web
CRITICAL 9.8
KEV
TeamCity — Unauthenticated RCE via Agent Polling Deserialization (CVE-2026-63077)
CVE-2026-63077 is an unauthenticated remote code execution vulnerability in JetBrains TeamCity. The agent polling subsystem accepts XML payloads from unregistered agents and deserializes them with XStream without any authentication or sanitization. An…
Patched
2026-08-09