securityonline.info 7/28/2026, 3:51:43 PM · external

TeamCity RCE Flaw CVE-2026-63077 (CVSS 9.8) Enables Unauthenticated Command Execution

TeamCity RCE Flaw CVE-2026-63077 (CVSS 9.8) Enables Unauthenticated Command Execution
Developing story vulnerability 3 articles tracked
Critical TeamCity unauthenticated code execution flaw patched (CVE-2026-63077)
CyberSIXT Evidence Panel
Primary Source blog.jetbrains.com
CISA KEV Not in KEV
Patch Patch Status Unknown

JETBRAINS has addressed a critical remote code execution (RCE) vulnerability in TeamCity, tracked as CVE-2026-63077, with a CVSS score of 9.8. This vulnerability affects all TeamCity On-Premises versions prior to 2026.1.3 and 2025.11.7, allowing unauthenticated attackers to execute operating system commands on the server via an insecure agent polling protocol. No evidence of exploitation exists currently, and patches are available. Users are advised to upgrade immediately to mitigate risks, especially since the issue can expose sensitive data and allow malicious code injections.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline