JetBrains is urging customers using on-premises versions of TeamCity to update immediately after fixing a critical security vulnerability that could allow attackers to remotely execute arbitrary code without authentication.
The vulnerability, tracked as CVE-2026-63077, has been assigned a CVSS severity score of 9.8 and affects all TeamCity On-Premises versions. The issue has been resolved in TeamCity 2025.11.7 and 2026.1.3, while TeamCity Cloud instances have already received the fix. JetBrains credited security researcher Antoni Tremblay, who reported the vulnerability on July 10, 2026.
According to JetBrains, the flaw could allow an unauthenticated attacker with HTTP or HTTPS access to a TeamCity server to bypass authentication and execute operating system commands with the same privileges as the TeamCity server process.
The vulnerability exists in the TeamCity agent polling protocol, enabling attackers to skip authentication checks and achieve remote code execution. If successfully exploited, attackers could access sensitive TeamCity data, configuration files, and stored credentials, or modify the server’s state depending on the permissions assigned to the TeamCity process.
For organizations that cannot immediately upgrade, JetBrains has also released a security patch plugin compatible with TeamCity versions 2017.1 and later. The company noted that the plugin only addresses CVE-2026-63077 and does not include the broader security improvements available in the latest TeamCity releases.
JetBrains said it is not aware of any evidence that the vulnerability has been exploited in the wild. However, it strongly recommends upgrading to the latest supported version as soon as possible.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
As an additional security measure, the company advises administrators to restrict access to internet-facing TeamCity servers by requiring VPN connections or placing them behind an additional security layer. JetBrains also warned that exposing TeamCity login pages or REST APIs directly to the internet can increase the risk of attackers exploiting newly disclosed vulnerabilities.





