JetBrains says a critical flaw in TeamCity On-Premises can let an attacker remotely take control of vulnerable build servers. The issue, CVE-2026-63077, is an authentication bypass in the agent polling protocol that can be exploited over HTTPS to run operating system commands with the server process's privileges. JetBrains says all TeamCity On-Premises versions are affected, TeamCity Cloud is already protected, and fixes are available in versions 2025.11.7 and 2026.1.3 plus a security patch plugin for TeamCity 2017.1+.
Why it matters: TeamCity often holds source code, build secrets, and deployment access, so compromise can cascade into software supply-chain and environment-wide damage. Organizations running TeamCity On-Premises should patch or install the security plugin immediately and restrict internet exposure behind a VPN or other access controls.
info@thehackernews.com (The Hacker News)
2026.08.06
95% relevant
This article updates the same underlying event by adding that CISA has flagged CVE-2026-63077 as actively exploited in the wild, increasing urgency beyond JetBrains' original patch warning.
Ionut Arghire
2026.08.06
97% relevant
This updates the same underlying event by adding that CISA has now placed CVE-2026-63077 in the Known Exploited Vulnerabilities catalog, confirming active exploitation and imposing a three-day federal patch deadline.
Ionut Arghire
2026.07.31
98% relevant
This article is a direct report on the same JetBrains TeamCity event, adding patch-version details (2025.11.7 and 2026.1.3), availability of a security patch plugin for 2017.1+, confirmation that TeamCity Cloud was mitigated, and vendor guidance on limiting exposure and separating servers from build agents.
Bill Toulas
2026.07.30
100% relevant
This article appears to be the first tracked item here for JetBrains' disclosure of CVE-2026-63077 in TeamCity On-Premises, including affected scope, fixed versions, and mitigation guidance.
← Back to all stories