Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
Overview
JetBrains has alerted users of on-premise TeamCity versions about a serious security vulnerability that could allow attackers to execute arbitrary commands on affected systems without needing to log in. This flaw, identified as CVE-2026-63077, has a high severity score of 9.8, indicating the potential for significant damage if exploited. It impacts all versions of TeamCity On-Premises, prompting JetBrains to recommend that users immediately update to the latest versions, 2025.11.7 or 2026.1.3, to safeguard their installations. TeamCity Cloud users are not affected, as the vulnerability has already been patched in that environment. This issue stresses the importance of timely software updates to prevent unauthorized access and control over systems.
Key Takeaways
- Affected Systems: TeamCity On-Premises versions; JetBrains
- Action Required: Users should update to TeamCity versions 2025.
- Timeline: Newly disclosed
Original Article Summary
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already
Impact
TeamCity On-Premises versions; JetBrains
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Users should update to TeamCity versions 2025.11.7 or 2026.1.3 to mitigate the vulnerability.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, Update, and 1 more.