JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover
ID: 3b0c59db-8ee5-59a0-bf8c-e19324ed2a71
STIX ID: report--3b0c59db-8ee5-59a0-bf8c-e19324ed2a71
Feed Name: Security Affairs
JetBrains released fixes for a critical unauthenticated remote code execution vulnerability in TeamCity On-Premises (CVE-2026-63077, CVSS 9.8) that allows attackers with HTTP(S) access to bypass authentication and execute OS commands via the agent polling protocol. All on-premise versions are impacted; users are advised to upgrade to 2025.11.7 or 2026.1.3 or install the provided security patch plugin, restrict network exposure (VPN, least-privilege, host separation), and apply other recommended controls; no active exploitation was reported at disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
