ON July 27, 2026, JetBrains announced a critical security vulnerability (CVE-2026-63077) affecting all versions of TeamCity On-Premises, allowing unauthenticated remote code execution. This vulnerability, classified under CVSS with a score of 9.8, enables cyber attackers to bypass authentication and execute commands with the privileges of the TeamCity server process.
JetBrains has advised users to urgently update to fixed versions (2025.11.7 or 2026.1.3) or apply a security patch plugin if upgrading is not possible. Rapid7 customers can assess their exposure to this vulnerability through available vulnerability checks. For further details, organizations are directed to the JetBrains security advisory.