Skip to content
cve — cve-2026-63077

grep -rl "CVE-2026-63077" ./articles

CVE-2026-63077

CVE-2026-63077 is a 9.8 unauthenticated RCE in TeamCity. CISA listed it as actively exploited on 5 August. Three days later, attackers used it against api.cadence.jetbrains.com — JetBrains' own hosted service, running JetBrains' own unpatched product — and left with a 2024 server backup, AWS IAM credentials and users' source code.

1 article — 2026-09-07

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

../cve — every identifier we have covered