Skip to content

Critical Security Vulnerability in TeamCity Enables Unauthenticated Code Execution

The Bottom Line: TeamCity On-Premises is vulnerable to unauthenticated code execution via CVE-2026-63077; patches are available in versions 2025.11.7 and 2026.1.3.

JetBrains has discovered a critical security vulnerability (CVE-2026-63077, CVSS 9.8) in on-premises versions of TeamCity that allows attackers to execute arbitrary code. The company is urging customers to update immediately.

JetBrains has publicly disclosed a vulnerability in TeamCity On-Premises, rated CVSS 9.8 and classified as critical. The vulnerability is identified as CVE-2026-63077 and affects all on-premises versions of TeamCity. Attackers could exploit this flaw to execute arbitrary code on affected systems without prior authentication.

Patches are available for TeamCity in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances are already protected against this vulnerability. Operators of on-premises installations should update their systems to one of the patched versions as soon as possible to prevent code execution by unauthenticated attackers.

Such a vulnerability poses a critical risk to organizations, as TeamCity is frequently used in CI/CD pipelines and build processes. Unauthorized access could lead to source code compromise, injection of malware into artifacts, or lateral movement within the infrastructure.


Source: thehackernews.com · Published 28 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: