JetBrains TeamCity vulnerability: how to find impacted assets
ID: c2e1fb54-c16d-536d-bced-505b9c0ad0a4
STIX ID: report--c2e1fb54-c16d-536d-bced-505b9c0ad0a4
Feed Name: runZero Blog
## JetBrains TeamCity critical RCE (CVE-2026-63077) JetBrains disclosed a critical remote code execution vulnerability (CVE-2026-63077, CVSS 9.8) in TeamCity On‑Premises that allows unauthenticated HTTP(S) attackers to bypass authentication and execute OS commands as the TeamCity server process; affected versions include all on‑premises releases prior to 2026.1.3 and 2025.11.7. The advisory describes high-impact consequences (credential theft, build/timeline compromise), references prior related CVEs, and strongly recommends upgrading to the fixed releases or applying the official security patch plugin.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
