Vulnerabilities

Critical Code Execution Vulnerability Patched in TeamCity 

Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol.

Vulnerability

JetBrains this week rolled out patches for a critical-severity vulnerability in TeamCity On-Premises that can be exploited without authentication.

Tracked as CVE-2026-63077 (CVSS score of 9.8), the security defect can be exploited via HTTP/S to bypass authentication and achieve remote code execution (RCE).

“An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,” JetBrains explains in its advisory.

Depending on the available privileges, an attacker could access TeamCity data, configurations, and credentials, could tamper with the server state, and could potentially compromise build artifacts and downstream CI/CD pipelines.

According to JetBrains, the flaw affects all TeamCity On-Premises versions. The company has already rolled out mitigations for TeamCity Cloud instances and has no evidence that the bug has been exploited in the wild.

“A fix for this vulnerability has been introduced in versions 2025.11.7 and 2026.1.3. We have also released a security patch plugin for 2017.1+ so that customers who are unable to upgrade can still patch their environments,” JetBrains announced.

Advertisement. Scroll to continue reading.

Users are advised to download and install either the latest version of TeamCity or the security patch plugin as soon as possible (the plugin resolves only this CVE, the company notes).

JetBrains also recommends limiting access to internet-facing TeamCity servers, running all servers with the minimum required operating system privileges, and using VPN connections or implementing additional protections to prevent unauthorized access.

“TeamCity servers should also run on dedicated hosts separate from build agents,” the company notes.

Related: Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms

Related: Chrome 151 Patches 370 Vulnerabilities

Related: Cisco Secure FMC Zero-Day Exploited in the Wild

Related: Critical VM Escape Vulnerability Patched in VMware ESXi

Related Content

Artificial Intelligence

Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container.

Vulnerabilities

The major browser update resolves roughly 80 critical- and high-severity security defects.

Vulnerabilities

The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices. 

Vulnerabilities

A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion.

Artificial Intelligence

The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.

Endpoint Security

Apple announced that dozens of vulnerabilities have been patched in each of its operating systems.

Funding/M&A

Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments.

Vulnerabilities

Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version