Critical JetBrains Flaw Allows Attackers to Execute Malicious Code Remotely – Update Now
ID: 7bbc9db3-9620-5454-b72e-a39e775597e4
STIX ID: report--7bbc9db3-9620-5454-b72e-a39e775597e4
Feed Name: cybersecurityNews.com
Threat Score
JetBrains disclosed CVE-2026-63077, a critical unauthenticated remote code execution flaw in TeamCity On-Premises that allows an attacker with HTTP/HTTPS access to execute OS commands as the TeamCity server process. Patches are available (TeamCity 2025.11.7 and 2026.1.3) and a security patch plugin supports older versions; JetBrains reports no known active exploitation but urges immediate remediation and additional network and privilege mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
