Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands
ID: 364203a8-9dc6-56bb-9fc5-a8698a98e3fd
STIX ID: report--364203a8-9dc6-56bb-9fc5-a8698a98e3fd
Feed Name: GBHackers
JetBrains disclosed CVE-2026-63077: a critical, unauthenticated remote command-execution vulnerability in TeamCity On‑Premises affecting all self-hosted versions; fixes are available in TeamCity 2025.11.7 and 2026.1.3 (TeamCity Cloud unaffected). Administrators should apply the vendor updates or the security patch plugin immediately and restrict access to TeamCity instances, as successful exploitation could expose secrets, build artifacts, and potentially compromise hosts and the software supply chain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
