JETBRAINS has issued patches for a critical vulnerability in TeamCity, identified as CVE-2026-63077, which allows unauthenticated code execution on affected on-premise servers, posing severe security risks. The flaw has a CVSS score of 9.8 and impacts all on-premise versions, while cloud instances are safe. Users are urged to upgrade to versions 2025.11.7 or 2026.1.3. A security patch plugin is also available for those unable to upgrade immediately. JetBrains emphasizes the importance of securing TeamCity servers by limiting network access and employing additional security measures.
JetBrains patches critical unauthenticated code flaw in TeamCity
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
JetBrains patches critical unauthenticated code flaw in TeamCity
securityaffairs.com
-
TeamCity flaw lets attackers run OS commands without login
cybersixt.com