logo

Critical JetBrains TeamCity Flaw Enables Unauthenticated Remote Code Execution

ID: a525e9b0-d2c1-550c-af6b-818c6c826701

STIX ID: report--a525e9b0-d2c1-550c-af6b-818c6c826701

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-07-31

Date Updated: 2026-07-31

Author: Divya

...
...

JetBrains disclosed a critical unauthenticated RCE in TeamCity On‑Premises (CVE-2026-63077) that allows attackers with network access to bypass authentication via the agent polling protocol and execute arbitrary OS commands. JetBrains released fixes in TeamCity 2025.11.7 and 2026.1.3 and a security patch plugin for supported older releases; TeamCity Cloud has mitigations and no evidence of active exploitation. Organizations are urged to upgrade or apply the plugin, restrict network exposure, run the server with minimal OS privileges, and isolate build infrastructure to reduce supply-chain and lateral-movement risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.