JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
PatchTeamCity On-PremisesOur summary
JetBrains has addressed a high-severity remote code execution flaw (CVE-2026-63077) impacting its self-hosted TeamCity On-Premises product. The vulnerability allows attackers to bypass authentication and execute arbitrary commands on the server, potentially leading to full system compromise. Admins are advised to update to version 2025.11.7 or 2026.1.3 immediately or apply the provided security patch plugin for older versions. JetBrains confirmed no active exploitation attempts have been observed.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.