logo

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)

ID: 518fe1c4-1bb8-518e-8086-36472a06f3d6

STIX ID: report--518fe1c4-1bb8-518e-8086-36472a06f3d6

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-07-28

Date Updated: 2026-07-28

Author: Zeljka Zorz

...
...

JetBrains patched a critical vulnerability (CVE-2026-63077) in TeamCity On-Premises that allows authentication bypass and OS command execution via the agent polling protocol; Cloud instances were already fixed and self-hosted servers should be upgraded to 2025.11.7 or 2026.1.3 (or use the security patch plugin), with JetBrains recommending network access restrictions, VPN/additional security layers, and least-privilege operation; no active exploitation was observed at the time of the advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.