CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3475

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

JetBrains disclosed CVE-2026-63077, a critical unauthenticated remote code execution vulnerability in TeamCity On-Premises with a CVSS score of 9.8, affecting all versions. Attackers exploiting the deserialization flaw via the agent polling protocol can execute arbitrary commands with server process privileges, read credentials, and compromise CI/CD pipelines. JetBrains published fixed versions (TeamCity 2025.11.7 and 2026.1.3) and a security patch plugin for older releases, with no reported active exploitation at disclosure.

Why it matters: Organizations running TeamCity On-Premises face critical remote code execution risk and must immediately patch or apply the security plugin to prevent unauthorized access to build pipelines and stored credentials.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

JetBrains disclosed CVE-2026-63077, a critical deserialization flaw in TeamCity On-Premises that allows unauthenticated attackers to execute arbitrary commands through the agent polling protocol with a CVSS score of 9.8. The vulnerability affects all versions and grants attackers access to stored credentials and the ability to manipulate continuous integration and continuous deployment pipelines. TeamCity Cloud is unaffected, while on-premises deployments must update immediately to versions 2025.11.7, 2026.1.3, or apply a security patch plugin if upgrading is not feasible.

Why it matters: Organizations running TeamCity On-Premises face immediate critical risk from unauthenticated remote code execution that could compromise build pipelines and credentials; patching or applying the security plugin is essential today.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

JetBrains disclosed CVE-2026-63077, a critical deserialization flaw in TeamCity On-Premises that allows unauthenticated attackers to execute arbitrary commands through the agent polling protocol with a CVSS score of 9.8. The vulnerability affects all versions and grants attackers access to stored credentials and the ability to manipulate continuous integration and continuous deployment pipelines. TeamCity Cloud is unaffected, while on-premises deployments must update immediately to versions 2025.11.7, 2026.1.3, or apply a security patch plugin if upgrading is not feasible.

Why it matters: Organizations running TeamCity On-Premises face immediate critical risk from unauthenticated remote code execution that could compromise build pipelines and credentials; patching or applying the security plugin is essential today.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary