CVE-2026-63077 is a critical deserialization of untrusted data vulnerability in JetBrains TeamCity On-Premises. An unauthenticated attacker with HTTP(S) access to a vulnerable TeamCity server can abuse the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. Successful exploitation can expose TeamCity data, configurations, and stored credentials. It can also allow changes to server state and potentially compromise build artifacts and downstream CI/CD pipelines. The vulnerability affects TeamCity versions before 2025.11.7 and 2026.1.3. CISA added the vulnerability to its KEV catalog on August 5, 2026, after exploitation was observed in the wild.