JetBrains warns TeamCity On-Premises users to patch critical remote-code-execution flaw CVE-2026-63077

JetBrains says a critical flaw in TeamCity On-Premises can let an attacker remotely take control of vulnerable build servers. The issue, CVE-2026-63077, is an authentication bypass in the agent polling protocol that can be exploited over HTTPS to run operating system commands with the server process's privileges. JetBrains says all TeamCity On-Premises versions are affected, TeamCity Cloud is already protected, and fixes are available in versions 2025.11.7 and 2026.1.3 plus a security patch plugin for TeamCity 2017.1+.
Why it matters: TeamCity often holds source code, build secrets, and deployment access, so compromise can cascade into software supply-chain and environment-wide damage. Organizations running TeamCity On-Premises should patch or install the security plugin immediately and restrict internet exposure behind a VPN or other access controls.

Sources

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
info@thehackernews.com (The Hacker News) 2026.08.06 95% relevant
This article updates the same underlying event by adding that CISA has flagged CVE-2026-63077 as actively exploited in the wild, increasing urgency beyond JetBrains' original patch warning.
Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability
Ionut Arghire 2026.08.06 97% relevant
This updates the same underlying event by adding that CISA has now placed CVE-2026-63077 in the Known Exploited Vulnerabilities catalog, confirming active exploitation and imposing a three-day federal patch deadline.
Critical Code Execution Vulnerability Patched in TeamCity
Ionut Arghire 2026.07.31 98% relevant
This article is a direct report on the same JetBrains TeamCity event, adding patch-version details (2025.11.7 and 2026.1.3), availability of a security patch plugin for 2017.1+, confirmation that TeamCity Cloud was mitigated, and vendor guidance on limiting exposure and separating servers from build agents.
JetBrains warns of critical TeamCity remote code execution flaw
Bill Toulas 2026.07.30 100% relevant
This article appears to be the first tracked item here for JetBrains' disclosure of CVE-2026-63077 in TeamCity On-Premises, including affected scope, fixed versions, and mitigation guidance.
← Back to all stories