CVE Tools

Critical Code Execution Vulnerability Patched in TeamCity

SecurityWeekBy Ionut Arghire

PatchJetBrains

Our summary

JetBrains has addressed a high-severity vulnerability in TeamCity On-Premises that allows unauthenticated attackers to execute arbitrary code remotely. Tracked as CVE-2026-63077 (CVSS score 9.8), the flaw impacts all on-premises editions and could allow access to sensitive data, server tampering, and CI/CD pipeline manipulation. Patches are available in versions 2025.11.7 and 2026.1.3, with a security plugin offered for older versions.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store