CVE Tools

JetBrains warns of critical TeamCity remote code execution flaw

BleepingComputerBy Bill Toulas

PatchJetBrains

Our summary

JetBrains has issued a warning about a severe vulnerability in its TeamCity On-Premises software, which could allow attackers to execute arbitrary code remotely. The flaw, identified as CVE-2026-63077, affects all versions of the on-premises edition and allows unauthorized users with HTTPS access to bypass authentication mechanisms. This could lead to full server compromise, including access to sensitive data and credentials. While no active exploitation has been observed yet, previous TeamCity vulnerabilities have been widely abused by ransomware groups and state-sponsored hackers. JetBrains recommends upgrading to version 2025.11.7 or later, or applying a security patch plugin for older versions.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store