NEW: Group Profiler — instant APT intel lookup. Try it →

CVE-2026-63077

Confirmed by 3 independent sources tracked by ThreatFilter. First reported 2026-07-29 16:16 UTC , most recent 2026-08-06 06:51 UTC.

CRITICAL 9.8 CISA KEV EXPLOITED jetbrains

Corroboration timeline

Each row is the first time that source reported this CVE, so the lag column shows how long each took relative to the earliest report. Independent corroboration is a confidence signal that a single advisory cannot give you.

  1. rapid7-blog 2026-07-29 16:16 UTC first report

    CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

  2. cisa-kev 2026-08-05 00:00 UTC +6d

    CVE-2026-63077 — JetBrains TeamCity: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

  3. thehackernews 2026-08-06 06:51 UTC +8d

    CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

How this page is built

ThreatFilter ingests 52 public threat-intelligence feeds. A page is published here only when at least 3 distinct sources report the same CVE — roughly 0.2% of the CVEs seen. Everything above is derived from those feeds; nothing is hand-written, and the timeline is the raw record of what each source published and when.

See the live advisory feed, the full source list, or the analyst tools.