importantSYS.SOURCE: The Hacker News• 2026-07-28T13:41:22+05:30
Critical TeamCity Vulnerability (CVE-2026-63077) Enables Unauthenticated Remote Code Execution
A critical vulnerability in TeamCity allows unauthenticated attackers to execute arbitrary OS commands via the agent polling protocol. JetBrains has released patches and a security plugin to address the issue, urging users to update immediately.
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution.
The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already
*** END OF TRANSMISSION ***