logo

Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands

ID: 364203a8-9dc6-56bb-9fc5-a8698a98e3fd

STIX ID: report--364203a8-9dc6-56bb-9fc5-a8698a98e3fd

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-07-28

Date Updated: 2026-07-28

Author: Divya

...
...

JetBrains disclosed CVE-2026-63077: a critical, unauthenticated remote command-execution vulnerability in TeamCity On‑Premises affecting all self-hosted versions; fixes are available in TeamCity 2025.11.7 and 2026.1.3 (TeamCity Cloud unaffected). Administrators should apply the vendor updates or the security patch plugin immediately and restrict access to TeamCity instances, as successful exploitation could expose secrets, build artifacts, and potentially compromise hosts and the software supply chain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.