JetBrains warns of critical TeamCity remote code execution flaw
ID: dd3e9e72-3ccd-55cc-af9c-9a38cf7f5619
STIX ID: report--dd3e9e72-3ccd-55cc-af9c-9a38cf7f5619
Feed Name: Bleeping Computer
JetBrains warned of a critical authentication-bypass vulnerability (CVE-2026-63077) in TeamCity On-Premises that allows an attacker with HTTPS access to bypass authentication via the agent polling protocol and execute arbitrary OS commands as the server process. All on-premises versions are affected; JetBrains released fixes in TeamCity 2025.11.7 and 2026.1.3 and a security patch plugin for older releases, and recommends upgrades, installing the patch plugin where available, and applying network protections for internet-facing servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
