Skip to content

Critical Security Vulnerability in JetBrains TeamCity Enables Code Execution

In a nutshell: A critical vulnerability in TeamCity jeopardizes the entire build and deployment pipeline and requires immediate patches.

JetBrains has closed a critical vulnerability in TeamCity that allows attackers to compromise CI/CD pipelines and execute arbitrary commands on the server.

JetBrains has announced and closed a critical security vulnerability in the CI/CD automation solution TeamCity. The vulnerability allows attackers to gain control over CI/CD pipelines and execute arbitrary commands on affected servers.

For CISOs, this vulnerability presents a significant risk: TeamCity is frequently deployed as a central component in development and deployment infrastructures. A compromise not only enables manipulation of build artifacts and deployments, but also lateral movement across the IT landscape as well as access to source code repositories, secrets and dependencies. Attackers could, for example, inject malware or backdoors into production software.

Affected organizations should immediately determine which TeamCity versions are in use and apply available security patches promptly. In parallel, it is recommended to review build logs, deployment histories and system access for signs of misuse.


Source: www.heise.de · Published July 29, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: