Critical JetBrains TeamCity Flaw Enables Remote Code Execution

JetBrains is warning users about a critical vulnerability in TeamCity On-Premises that allows attackers to bypass authentication and execute arbitrary code on affected servers. The flaw, tracked as CVE-2026-63077, can be exploited by anyone with HTTPS access to a TeamCity server through the agent polling protocol. All versions of TeamCity On-Premises are vulnerable, while TeamCity Cloud customers are already protected.

The vulnerability poses serious risks to software development environments. Successful exploitation could expose sensitive data, stored credentials, configurations, and compromise build artifacts or entire CI/CD pipelines. Although there is no evidence of active exploitation yet, TeamCity flaws have historically attracted attention from ransomware gangs and state-sponsored attackers, making rapid patching essential.

JetBrains has released fixes in TeamCity versions 2025.11.7 and 2026.1.3, and a security patch plugin is available for older deployments going back to 2017.1. The company also advises administrators to restrict internet exposure of TeamCity servers by using VPNs and other protective layers, noting that even exposing the login page can give attackers an entry point for newly discovered vulnerabilities.

Read More at the original source →