As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
JetBrains disclosed CVE-2026-63077, a critical unauthenticated remote code execution vulnerability in TeamCity On-Premises with a CVSS score of 9.8, affecting all versions. Attackers exploiting the deserialization flaw via the agent polling protocol can execute arbitrary commands with server process privileges, read credentials, and compromise CI/CD pipelines. JetBrains published fixed versions (TeamCity 2025.11.7 and 2026.1.3) and a security patch plugin for older releases, with no reported active exploitation at disclosure.
Why it matters: Organizations running TeamCity On-Premises face critical remote code execution risk and must immediately patch or apply the security plugin to prevent unauthorized access to build pipelines and stored credentials.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
JetBrains disclosed CVE-2026-63077, a critical deserialization flaw in TeamCity On-Premises that allows unauthenticated attackers to execute arbitrary commands through the agent polling protocol with a CVSS score of 9.8. The vulnerability affects all versions and grants attackers access to stored credentials and the ability to manipulate continuous integration and continuous deployment pipelines. TeamCity Cloud is unaffected, while on-premises deployments must update immediately to versions 2025.11.7, 2026.1.3, or apply a security patch plugin if upgrading is not feasible.
Why it matters: Organizations running TeamCity On-Premises face immediate critical risk from unauthenticated remote code execution that could compromise build pipelines and credentials; patching or applying the security plugin is essential today.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
JetBrains disclosed CVE-2026-63077, a critical deserialization flaw in TeamCity On-Premises that allows unauthenticated attackers to execute arbitrary commands through the agent polling protocol with a CVSS score of 9.8. The vulnerability affects all versions and grants attackers access to stored credentials and the ability to manipulate continuous integration and continuous deployment pipelines. TeamCity Cloud is unaffected, while on-premises deployments must update immediately to versions 2025.11.7, 2026.1.3, or apply a security patch plugin if upgrading is not feasible.
Why it matters: Organizations running TeamCity On-Premises face immediate critical risk from unauthenticated remote code execution that could compromise build pipelines and credentials; patching or applying the security plugin is essential today.
- Source published
- First seen by Cybersecurity Tracker