Vulnerabilities

Critical Code Execution Vulnerability Patched in TeamCity 

Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol.

Vulnerability

JetBrains this week rolled out patches for a critical-severity vulnerability in TeamCity On-Premises that can be exploited without authentication.

Tracked as CVE-2026-63077 (CVSS score of 9.8), the security defect can be exploited via HTTP/S to bypass authentication and achieve remote code execution (RCE).

“An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,” JetBrains explains in its advisory.

Depending on the available privileges, an attacker could access TeamCity data, configurations, and credentials, could tamper with the server state, and could potentially compromise build artifacts and downstream CI/CD pipelines.

According to JetBrains, the flaw affects all TeamCity On-Premises versions. The company has already rolled out mitigations for TeamCity Cloud instances and has no evidence that the bug has been exploited in the wild.

“A fix for this vulnerability has been introduced in versions 2025.11.7 and 2026.1.3. We have also released a security patch plugin for 2017.1+ so that customers who are unable to upgrade can still patch their environments,” JetBrains announced.

Advertisement. Scroll to continue reading.

Users are advised to download and install either the latest version of TeamCity or the security patch plugin as soon as possible (the plugin resolves only this CVE, the company notes).

JetBrains also recommends limiting access to internet-facing TeamCity servers, running all servers with the minimum required operating system privileges, and using VPN connections or implementing additional protections to prevent unauthorized access.

“TeamCity servers should also run on dedicated hosts separate from build agents,” the company notes.

Related: Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms

Related: Chrome 151 Patches 370 Vulnerabilities

Related: Cisco Secure FMC Zero-Day Exploited in the Wild

Related: Critical VM Escape Vulnerability Patched in VMware ESXi

Related Content

Vulnerabilities

The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks.

Email Security

An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges.

Nation-State

The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely.

Vulnerabilities

The vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator.

Vulnerabilities

The flaw allows attackers to send files and execute them without authorization through an active remote session.

Vulnerabilities

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.

Vulnerabilities

A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version