logo

CVE-2026-63077 Exposes TeamCity Servers to Unauthenticated RCE

ID: c5f88e56-4862-536c-9ba0-5d87b0f9285d

STIX ID: report--c5f88e56-4862-536c-9ba0-5d87b0f9285d

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2026-07-30

Date Updated: 2026-07-30

Author: Ashish Khaitan

...
...

A critical unauthenticated remote command-execution vulnerability (CVE-2026-63077) affects TeamCity On-Premises instances exposed over HTTP(S). The vendor has released fixes in TeamCity 2025.11.7 and 2026.1.3 and provides a security patch plugin for older installations; administrators are urged to update or deploy the plugin and restrict internet exposure to mitigate potential compromise of server data, credentials, and CI/CD pipelines. No evidence of active exploitation in TeamCity Cloud has been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.