logo

TeamCity RCE Vulnerability: Critical Authentication Bypass

ID: 1d7c1eab-240f-5f1e-b893-f5d08060d7af

STIX ID: report--1d7c1eab-240f-5f1e-b893-f5d08060d7af

Feed Name: CyberNexora News

Threat Score
78/100

Date Published: 2026-07-31

Date Updated: 2026-08-01

Author: Debolina Barik

...
...

**Executive summary:** JetBrains disclosed CVE-2026-63077, a critical unauthenticated remote code execution vulnerability in TeamCity On‑Premises that allows attackers with HTTP/HTTPS access to bypass agent polling authentication and execute arbitrary commands; fixes are available in TeamCity 2025.11.7 and 2026.1.3 and a temporary patch plugin was provided for older releases, while JetBrains reported no evidence of active exploitation at the time of disclosure—organizations should patch immediately, restrict external access, rotate credentials, and monitor CI/CD pipelines to reduce supply‑chain and operational risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.