Critical TeamCity Flaw Could Let Unauthenticated Attackers Execute Server Commands
ID: 37053202-c914-5fc0-ad8d-a68857862d86
STIX ID: report--37053202-c914-5fc0-ad8d-a68857862d86
Feed Name: TechRepublic Security
JetBrains released emergency fixes for CVE-2026-63077, a critical unauthenticated command-execution vulnerability in TeamCity On‑Premises servers reachable over HTTP(S). Administrators are urged to upgrade to TeamCity 2025.11.7 or 2026.1.3 (or apply the vendor’s security plugin for older supported releases), restrict network exposure until patched, and audit credentials, builds, and connected infrastructure; JetBrains reported no known active exploitation at the time of disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
