JetBrains security advisory (AV26-752) – Update 1
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-752 Date: July 28, 2026 Updated: August 5, 2026 As of July 27, 2026, JetBrains is affected by a vulnerability in the following product: TeamCity Prior to 2026.1.3, 2025.11.7 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Update 1 On August 5, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-63077 to their Known Exploited Vulnerabilities (KEV) Database. Fixed security issues Security - The JetBrains Blog CISA KEV: CVE-2026-63077
CSIRTS triage
- What
- A vulnerability has been identified in TeamCity.
- Who is affected
- Users of TeamCity versions prior to the specified versions.
- Urgency
- Remediation is recommended but not urgent as the vulnerabilities are not actively exploited.
- Action
- Users should update to the latest versions 2026.1.3 or 2025.11.7.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch TeamCity
Get an email when a new TeamCity advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/jetbrains-security-advisory-av26-752
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-63077Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.7% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-63077 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalexploited[NEW] [high] JetBrains TeamCity: Vulnerability allows code executioncert-bund
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
- criticalexploitedCVE-2026-63077: JetBrains TeamCity Deserialization of Untrusted Data Vulnerabilitycisa-kev
- criticalCVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was pos…nvd
More from Canadian Centre for Cyber Security
- criticalGitLab security advisory (AV26-917)2026-09-11
- unknownJFrog security advisory (AV26-867) – Update 22026-09-11
- unknownn8n security advisory (AV26-916)2026-09-11
- unknownConnectWise security advisory (AV26-903) – Update 12026-09-11
- criticalProgress security advisory (AV26-915)2026-09-11