www.rapid7.com 29 Jul 2026, 16:16 UTC

Serious JetBrains TeamCity Flaw Lets Attackers Run Code Remotely

Serious JetBrains TeamCity Flaw Lets Attackers Run Code Remotely
CyberSIXT Evidence Panel
Primary Source blog.jetbrains.com
CISA KEV Listed in KEV
Patch Patch Available

ON July 27, 2026, JetBrains announced a critical security vulnerability (CVE-2026-63077) affecting all versions of TeamCity On-Premises, allowing unauthenticated remote code execution. This vulnerability, classified under CVSS with a score of 9.8, enables cyber attackers to bypass authentication and execute commands with the privileges of the TeamCity server process.

JetBrains has advised users to urgently update to fixed versions (2025.11.7 or 2026.1.3) or apply a security patch plugin if upgrading is not possible. Rapid7 customers can assess their exposure to this vulnerability through available vulnerability checks. For further details, organizations are directed to the JetBrains security advisory.

View Primary Source Via www.rapid7.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline