CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
PatchJetBrains TeamCityOur summary
JetBrains has addressed a critical remote code execution vulnerability, CVE-2026-63077, impacting all versions of TeamCity On-Premises. The flaw allows unauthenticated attackers to execute arbitrary commands on the server through the agent polling protocol. With a CVSS score of 9.8, this high-severity issue could lead to full system compromise and exposure of sensitive credentials. Affected organizations are urged to update to TeamCity 2025.11.7 or 2026.1.3 immediately. Alternatively, a security patch plugin is available for older versions starting from 2017.1. Cloud users are unaffected.
Below is the opening; the full story is at Rapid7 Blog.
From Rapid7 Blog
Overview
On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077">CVE-2026-63077, a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8. An unauthenticated remote attacker with HTTP(S) access to a TeamCity server can exploit the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.