logo

JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover

ID: 3b0c59db-8ee5-59a0-bf8c-e19324ed2a71

STIX ID: report--3b0c59db-8ee5-59a0-bf8c-e19324ed2a71

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-07-28

Date Updated: 2026-07-28

Author: Pierluigi Paganini

...
...

JetBrains released fixes for a critical unauthenticated remote code execution vulnerability in TeamCity On-Premises (CVE-2026-63077, CVSS 9.8) that allows attackers with HTTP(S) access to bypass authentication and execute OS commands via the agent polling protocol. All on-premise versions are impacted; users are advised to upgrade to 2025.11.7 or 2026.1.3 or install the provided security patch plugin, restrict network exposure (VPN, least-privilege, host separation), and apply other recommended controls; no active exploitation was reported at disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.