Back to Feed
VulnerabilitiesJul 31, 2026

Critical Code Execution Vulnerability Patched in TeamCity

JetBrains patches critical CVE-2026-63077 in TeamCity allowing unauthenticated RCE via agent polling protocol.

Summary

JetBrains released patches for CVE-2026-63077, a critical vulnerability (CVSS 9.8) in TeamCity On-Premises that allows unauthenticated remote code execution through the agent polling protocol. The flaw affects all TeamCity On-Premises versions and could enable attackers to execute arbitrary commands, access credentials, and compromise CI/CD pipelines. Fixes are available in TeamCity versions 2025.11.7 and 2026.1.3, with a security patch plugin available for older versions.

Full text

JetBrains this week rolled out patches for a critical-severity vulnerability in TeamCity On-Premises that can be exploited without authentication. Tracked as CVE-2026-63077 (CVSS score of 9.8), the security defect can be exploited via HTTP/S to bypass authentication and achieve remote code execution (RCE). “An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,” JetBrains explains in its advisory. Depending on the available privileges, an attacker could access TeamCity data, configurations, and credentials, could tamper with the server state, and could potentially compromise build artifacts and downstream CI/CD pipelines. According to JetBrains, the flaw affects all TeamCity On-Premises versions. The company has already rolled out mitigations for TeamCity Cloud instances and has no evidence that the bug has been exploited in the wild. “A fix for this vulnerability has been introduced in versions 2025.11.7 and 2026.1.3. We have also released a security patch plugin for 2017.1+ so that customers who are unable to upgrade can still patch their environments,” JetBrains announced.Advertisement. Scroll to continue reading. Users are advised to download and install either the latest version of TeamCity or the security patch plugin as soon as possible (the plugin resolves only this CVE, the company notes). JetBrains also recommends limiting access to internet-facing TeamCity servers, running all servers with the minimum required operating system privileges, and using VPN connections or implementing additional protections to prevent unauthorized access. “TeamCity servers should also run on dedicated hosts separate from build agents,” the company notes. Related: Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms Related: Chrome 151 Patches 370 Vulnerabilities Related: Cisco Secure FMC Zero-Day Exploited in the Wild Related: Critical VM Escape Vulnerability Patched in VMware ESXi Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms US and Allies Update SBOM GuidanceChrome 151 Patches 370 VulnerabilitiesMate Security Raises $35 Million for Agentic SOCUS, Australia Release OT Isolation Guidance for Critical Infrastructure Spur Raises $200 Million for IP Intelligence PlatformJFrog Zero-Days Exploited in OpenAI-Hugging Face HackShinyHunters Claims Ernst & Young Hack Latest News CareCloud Data Breach Impacts Over 350,000CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCsBank of America to Acquire Cybersecurity Firm MDSecOkta to Acquire Identity Threat Detection Firm PermisoTimeless Compliance: Why Better Questions Beat Bigger FrameworksDataBahn Raises $40 Million for Agentic Data Pipeline ManagementDiscern Security Raises $13 Million in Series A FundingCantina Emerges From Stealth With $8 Million in Funding Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveAlex Levinson has been named Executive Director at the National Collegiate Cyber Defense Competition.Hack The Box has appointed Konstantinos Dolkas as CTO and has promoted Christine Bartlett to CMO.The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER).More People On The MoveExpert Insights Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-63077

Entities

JetBrains (vendor)TeamCity (product)