< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

JetBrains releases patches for critical TeamCity On-Premises remote code execution flaw

On July 27, 2026 JetBrains disclosed CVE-2026-63077, a critical unauthenticated remote code execution vulnerability affecting all versions of TeamCity On-Premises. The flaw is a deserialization issue in the agent polling protocol and carries a CVSS score of 9.8.

Exploitation allows an attacker with HTTP(S) access to bypass authentication checks and execute arbitrary operating‑system commands with the privileges of the TeamCity server process, potentially reading stored credentials and compromising CI/CD pipelines. JetBrains reported no evidence of active exploitation.

The vendor urges administrators to upgrade immediately to TeamCity 2025.11.7 or 2026.1.3. Installations that cannot upgrade may apply a dedicated security‑patch plugin for versions 2017.1 and later. TeamCity Cloud customers are not affected. Additional defensive measures include restricting network access to the server.

Entities

Antoni Tremblay · JetBrains · TeamCity