www.rapid7.com 7/29/2026, 5:31:41 PM · external

Serious JetBrains TeamCity Flaw Lets Attackers Run Code Remotely

Serious JetBrains TeamCity Flaw Lets Attackers Run Code Remotely
Developing story vulnerability 4 articles tracked
Critical TeamCity unauthenticated code execution flaw patched (CVE-2026-63077)
CyberSIXT Evidence Panel
Primary Source blog.jetbrains.com
CISA KEV Not in KEV
Patch Patch Status Unknown

ON July 27, 2026, JetBrains announced a critical security vulnerability (CVE-2026-63077) affecting all versions of TeamCity On-Premises, allowing unauthenticated remote code execution. This vulnerability, classified under CVSS with a score of 9.8, enables cyber attackers to bypass authentication and execute commands with the privileges of the TeamCity server process.

JetBrains has advised users to urgently update to fixed versions (2025.11.7 or 2026.1.3) or apply a security patch plugin if upgrading is not possible. Rapid7 customers can assess their exposure to this vulnerability through available vulnerability checks. For further details, organizations are directed to the JetBrains security advisory.

View Primary Source Via www.rapid7.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline