CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution flaw in JetBrains TeamCity's agent polling protocol, entered CISA's Known Exploited Vulnerabilities catalog on August 5, 2026. The fix exists only in 2025.11.7 and 2026.1.3 — nine end-of-life version lines, from 2022.04 through 2025.07, will never receive it. What a compromised CI server means, and the upgrade-or-isolate decision.
Which versions get a fix — and which are permanently exposed
| Version line | Status | Released | End of life | Fix for CVE-2026-63077? |
|---|---|---|---|---|
| 2026.1 | Supported | May 11, 2026 | — | Yes — 2026.1.3 |
| 2025.11 | Supported | Nov 27, 2025 | — | Yes — 2025.11.7 |
| 2025.07 | EOL | Jul 23, 2025 | May 11, 2026 | Never |
| 2025.03 | EOL | Mar 20, 2025 | Nov 27, 2025 | Never |
| 2024.12 | EOL | Dec 5, 2024 | Jul 23, 2025 | Never |
| 2024.07 | EOL | Jul 18, 2024 | Mar 20, 2025 | Never |
| 2024.03 | EOL | Mar 27, 2024 | Dec 5, 2024 | Never |
| 2023.11 | EOL | Nov 28, 2023 | Jul 18, 2024 | Never |
| 2023.05 | EOL | May 26, 2023 | Mar 27, 2024 | Never |
| 2022.10 | EOL | Oct 27, 2022 | Nov 28, 2023 | Never |
| 2022.04 | EOL | Apr 28, 2022 | May 26, 2023 | Never |
What's covered
- Your build server is your most-trusted machine
- Thirty seconds: which TeamCity are you running?
- Which versions get a fix — and which are permanently exposed
- The upgrade-or-isolate decision
Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-teamcity-cve-2026-63077
Top comments (0)