[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$frXItxloLBpGlXE6nbqSLOfNTR8Ive4PHIUML3htg6Ns":3},{"article":4,"iocs":37},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"4bb97193-6609-45ba-ab5c-bc41c4dcf778","Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In","critical-teamcity-flaw-could-let-attackers-run-os-commands-without-logging-in-266950","JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already","JetBrains has released updates for its TeamCity CI\u002FCD platform to address a critical vulnerability (CVE-2026-63077) that allows unauthenticated attackers to execute arbitrary OS commands. The flaw affects all on-premise versions and has a CVSS score of 9.8. While TeamCity Cloud instances are already updated, on-premise users are urged to upgrade or apply a security patch plugin. There is currently no evidence of the vulnerability being exploited in the wild.","Critical TeamCity flaw allows unauthenticated attackers to execute OS commands.","Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In Ravie LakshmananJul 28, 2026Vulnerability \u002F Enterprise Security JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already been updated. JetBrains has credited Antoni Tremblay with discovering and reporting the flaw on July 10, 2026. \"If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,\" JetBrains said. The flaw allows unauthenticated remote code execution via the agent polling protocol to sidestep authentication checks and achieve command execution. Depending on the privileges granted to the TeamCity server process, a successful compromise can lead to the exposure of TeamCity data, configurations, and stored credentials, or modification of server state. Besides releasing versions 2025.11.7 and 2026.1.3, JetBrains has released a security patch plugin for versions 2017.1+ so that customers who are unable to apply an update can still patch their environments. There is no evidence to indicate that the flaw has been exploited in the wild. \"The security patch plugin will address only the vulnerability described above (CVE-2026-63077),\" JetBrains cautioned. \"We always recommend upgrading your server to the latest version to benefit from many other security updates.\" As best practices, customers are advised to consider requiring VPN connections or implementing an extra layer of security to prevent unauthorized access to internet-facing TeamCity servers. \"Even exposing the TeamCity login screen or REST API can provide attackers with potential entry points to exploit newly disclosed vulnerabilities,\" it added. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Application Security, Authentication bypass, CI\u002FCD Security, DevOps, enterprise security, remote code execution, server security, Software Security, Vulnerability ⚡ Top Stories This Week New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable ⭐ Featured Resources Identity Fraud Is Changing Fast. See the Attacks Businesses Face in 2026 What 25 Million Alerts Reveal About the Threats SOCs Ignore How to Find and Control Every Script Running Through Your Marketing Stack Modern SASE Guide: Close the Gaps Traditional Network Security Cannot See","https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fcritical-teamcity-flaw-could-let.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEiiX3xcF2Bm9BY5obe-T5JItuKynq8bPijOxp14p5damNEjPGtAbYyuLSqp6vKN_KkhPx1qYeTXHxpgnZllCrtLvDaDuJNyHpY1qV0i8KWCe79_bnFtBtTRPCTU28LcN7OFM26h_WZdxeM3KPWBK4dlp0jY8JKrs1UILNR0qRgtxhKJqCcrht69sc3gcwsU\u002Fs1600\u002Ftc.jpg","2026-07-28T08:11:22+00:00","2026-07-28T10:00:19.026971+00:00",8,[18,21],{"name":19,"type":20},"TeamCity","product",{"name":22,"type":23},"JetBrains","vendor","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":24,"icon":26,"name":27,"slug":28},null,"Vulnerabilities","vulnerabilities",[30,35],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":36},{"id":24,"icon":26,"name":27,"slug":28},[38],{"type":39,"value":40,"context":41},"cve","CVE-2026-63077","Critical vulnerability allowing arbitrary code execution in TeamCity"]