securityaffairs.com 28 Jul 2026, 11:17 UTC

JetBrains patches critical unauthenticated code flaw in TeamCity

JetBrains patches critical unauthenticated code flaw in TeamCity
CyberSIXT Evidence Panel
Primary Source blog.jetbrains.com
CISA KEV Listed in KEV
Patch Patch Available

JETBRAINS has issued patches for a critical vulnerability in TeamCity, identified as CVE-2026-63077, which allows unauthenticated code execution on affected on-premise servers, posing severe security risks. The flaw has a CVSS score of 9.8 and impacts all on-premise versions, while cloud instances are safe. Users are urged to upgrade to versions 2025.11.7 or 2026.1.3. A security patch plugin is also available for those unable to upgrade immediately. JetBrains emphasizes the importance of securing TeamCity servers by limiting network access and employing additional security measures.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline