{"data":{"id":"aac9adce-77d4-4c34-852e-fc3b8c68fa02","title":"CVE-2026-63077: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability","summary":"JetBrains TeamCity has a deserialization of untrusted data vulnerability (a flaw where the software unsafely processes data from untrusted sources, allowing attackers to execute malicious code), which allows unauthenticated attackers to gain RCE (remote code execution, the ability to run commands on a system they don't control) through the agent polling protocol. This vulnerability is actively being exploited by attackers.","solution":"Apply mitigations in accordance with vendor instructions (JetBrains). Follow CISA's BOD 26-04 guidance for patching based on risk and the 'Forensics Triage Requirements' document. For cloud services, follow applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. Evaluate each system's internet exposure and ensure adherence to BOD 26-04 patching guidelines by the due date of 2026-08-08. See the JetBrains TeamCity blog and security issues page for specific patches or updates.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63077","publishedAt":"2026-08-05T00:00:00.000Z","cveId":"CVE-2026-63077","cweIds":["CWE-502"],"cvssScore":null,"cvssSeverity":null,"severity":"critical","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["JetBrains TeamCity"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"active","epssScore":0.00649,"patchAvailable":true,"disclosureDate":"2026-08-05T00:00:00.000Z","capecIds":["CAPEC-586"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":["AML.T0010"]}}