CVE Tools

Teamcity

276 CVEs tracked. 4 of them are in CISA KEV.

This hub aggregates every CVE we track for Teamcity, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Teamcity CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Teamcity CVEs per month
MonthCVEs
2024-105
2024-110
2024-129
2025-013
2025-022
2025-033
2025-043
2025-054
2025-065
2025-0711
2025-083
2025-093
2025-100
2025-110
2025-1211
2026-010
2026-023
2026-030
2026-040
2026-0512
2026-060
2026-077
2026-080
2026-090

Severity

How the 276 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical197%
  • High4115%
  • Medium18667%
  • Low3011%

Latest CVEs

The 15 most recently published vulnerabilities affecting Teamcity.

  1. CVE-2026-63077In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol9.8
  2. CVE-2026-65907In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible9.1
  3. CVE-2026-65906In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible8.8
  4. CVE-2026-59796In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks8.1
  5. CVE-2026-59795In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible8.1
  6. CVE-2026-59794In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data7.3
  7. CVE-2026-59793In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration8.8
  8. CVE-2026-49380In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible3.1
  9. CVE-2026-49381In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible3.4
  10. CVE-2026-49379In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names6.5
  11. CVE-2026-49378In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion4.3
  12. CVE-2026-49377In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters4.3
  13. CVE-2026-49376In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin6.5
  14. CVE-2026-49375In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page6.1
  15. CVE-2026-49374In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters7.6

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store