Monday, September 7, 2026

Critical TeamCity Flaw Lets Unauthenticated Attackers Execute System Commands

JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on affected servers.

The issue impacts every version of the self-hosted continuous integration and continuous delivery platform, making it urgent for organizations that expose TeamCity instances over HTTP or HTTPS to apply patches.

JetBrains has released fixes in TeamCity versions 2025.11.7 and 2026.1.3, urging administrators to update immediately. Customers using TeamCity Cloud are not affected and do not need to take any action, as mitigations have already been implemented in the hosted service.

Critical TeamCity Flaw

According to JetBrains, the vulnerability can be exploited with just network access to the TeamCity server’s HTTP(S) interface; attackers do not need valid credentials.

The flaw exists in the TeamCity agent polling protocol, allowing attackers to bypass authentication checks and execute arbitrary commands with the privileges assigned to the TeamCity server process.

This issue is particularly concerning for organizations using TeamCity to manage source code builds, deployment workflows, package repositories, and secrets necessary for CI/CD processes.

If successfully exploited, attackers could gain access to sensitive TeamCity data, server configuration files, stored credentials, build parameters, and potentially to source code or deployment artifacts.

If the TeamCity service operates with elevated permissions, the impact may extend beyond the application server, potentially compromising the entire host.

Attackers could also manipulate build artifacts or alter pipeline configurations, creating a serious software supply-chain risk for affected organizations.

The issue was privately reported to JetBrains on July 10, 2026, by security researcher Antoni Tremblay through the vendor’s coordinated vulnerability disclosure process.

JetBrains stated it was unaware of any active exploitation at the time it published its advisory on July 27. However, the unauthenticated nature of this vulnerability, along with the public availability of patches and detailed technical context, means that TeamCity servers exposed to the internet should be considered high-priority remediation targets.

Organizations should upgrade their TeamCity On-Premises installations to version 2025.11.7 or 2026.1.3 using the vendor’s installer or the product’s automatic update mechanism.

Administrators unable to complete a full upgrade immediately can install JetBrains’ dedicated security patch plugin, which supports TeamCity versions 2017.1 and later.

For instances running TeamCity 2024.03 or newer, security patches can be reviewed through the Administration > Updates interface.

Servers running versions from 2017.1 through 2018.1 will require a restart following plugin installation. At the same time, later releases can enable the plugin without needing to restart.

The patch plugin addresses only CVE-2026-63077, so organizations should still plan for a full upgrade to obtain additional security fixes.

As part of a defense-in-depth strategy, JetBrains recommends restricting access to TeamCity to trusted networks, placing internet-facing deployments behind a VPN or an additional access control layer, running the service with the minimum required privileges, and hosting TeamCity servers separately from build agents.

ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Hackers Actively Exploiting MikroTik RouterOS MikroTrick Flaws to Take Full Control of Routers

Threat actors are actively exploiting critical vulnerabilities in MikroTik...

CrowdStrike Launches SafeMind Agentic AI Cybersecurity System Built With NVIDIA Nemotron

CrowdStrike has launched SafeMind, an AI-driven cybersecurity system developed...

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Chainguard has surpassed 1 billion container build manifests, doubling...

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Russian state-sponsored threat actor BlueDelta, also tracked as APT28,...

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS)...

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged...

Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours

A threat actor used frontier artificial-intelligence models and attack-specific...

Related Articles

Recent News