CVE-2026-63077 Exposes TeamCity Servers to Unauthenticated RCE
ID: c5f88e56-4862-536c-9ba0-5d87b0f9285d
STIX ID: report--c5f88e56-4862-536c-9ba0-5d87b0f9285d
Feed Name: The Cyber Express
A critical unauthenticated remote command-execution vulnerability (CVE-2026-63077) affects TeamCity On-Premises instances exposed over HTTP(S). The vendor has released fixes in TeamCity 2025.11.7 and 2026.1.3 and provides a security patch plugin for older installations; administrators are urged to update or deploy the plugin and restrict internet exposure to mitigate potential compromise of server data, credentials, and CI/CD pipelines. No evidence of active exploitation in TeamCity Cloud has been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
