JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
ID: 518fe1c4-1bb8-518e-8086-36472a06f3d6
STIX ID: report--518fe1c4-1bb8-518e-8086-36472a06f3d6
Feed Name: Help Net Security
JetBrains patched a critical vulnerability (CVE-2026-63077) in TeamCity On-Premises that allows authentication bypass and OS command execution via the agent polling protocol; Cloud instances were already fixed and self-hosted servers should be upgraded to 2025.11.7 or 2026.1.3 (or use the security patch plugin), with JetBrains recommending network access restrictions, VPN/additional security layers, and least-privilege operation; no active exploitation was observed at the time of the advisory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
