logo

JetBrains warns of critical TeamCity remote code execution flaw

ID: dd3e9e72-3ccd-55cc-af9c-9a38cf7f5619

STIX ID: report--dd3e9e72-3ccd-55cc-af9c-9a38cf7f5619

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-07-30

Date Updated: 2026-07-30

Author: Bill Toulas

...
...

JetBrains warned of a critical authentication-bypass vulnerability (CVE-2026-63077) in TeamCity On-Premises that allows an attacker with HTTPS access to bypass authentication via the agent polling protocol and execute arbitrary OS commands as the server process. All on-premises versions are affected; JetBrains released fixes in TeamCity 2025.11.7 and 2026.1.3 and a security patch plugin for older releases, and recommends upgrades, installing the patch plugin where available, and applying network protections for internet-facing servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.