logo

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

ID: 574d1b01-9e3a-508a-8b7d-47839f81463c

STIX ID: report--574d1b01-9e3a-508a-8b7d-47839f81463c

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-07-28

Date Updated: 2026-07-28

Author: [email protected] (The Hacker News)

...
...

JetBrains disclosed a critical unauthenticated RCE vulnerability (CVE-2026-63077, CVSS 9.8) affecting all TeamCity on‑premises versions, fixed in 2025.11.7 and 2026.1.3; a security patch plugin is available for older versions and TeamCity Cloud has been updated. If exploited via the agent polling protocol, an attacker could bypass authentication to execute OS commands as the TeamCity process, potentially exposing configurations and stored credentials; JetBrains reports no observed in-the-wild exploitation and urges updates or mitigations such as VPNs or additional access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.