JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on affected servers.
The issue impacts every version of the self-hosted continuous integration and continuous delivery platform, making it urgent for organizations that expose TeamCity instances over HTTP or HTTPS to apply patches.
JetBrains has released fixes in TeamCity versions 2025.11.7 and 2026.1.3, urging administrators to update immediately. Customers using TeamCity Cloud are not affected and do not need to take any action, as mitigations have already been implemented in the hosted service.
Critical TeamCity Flaw
According to JetBrains, the vulnerability can be exploited with just network access to the TeamCity server’s HTTP(S) interface; attackers do not need valid credentials.
The flaw exists in the TeamCity agent polling protocol, allowing attackers to bypass authentication checks and execute arbitrary commands with the privileges assigned to the TeamCity server process.
This issue is particularly concerning for organizations using TeamCity to manage source code builds, deployment workflows, package repositories, and secrets necessary for CI/CD processes.
If successfully exploited, attackers could gain access to sensitive TeamCity data, server configuration files, stored credentials, build parameters, and potentially to source code or deployment artifacts.
If the TeamCity service operates with elevated permissions, the impact may extend beyond the application server, potentially compromising the entire host.
Attackers could also manipulate build artifacts or alter pipeline configurations, creating a serious software supply-chain risk for affected organizations.
The issue was privately reported to JetBrains on July 10, 2026, by security researcher Antoni Tremblay through the vendor’s coordinated vulnerability disclosure process.
JetBrains stated it was unaware of any active exploitation at the time it published its advisory on July 27. However, the unauthenticated nature of this vulnerability, along with the public availability of patches and detailed technical context, means that TeamCity servers exposed to the internet should be considered high-priority remediation targets.
Organizations should upgrade their TeamCity On-Premises installations to version 2025.11.7 or 2026.1.3 using the vendor’s installer or the product’s automatic update mechanism.
Administrators unable to complete a full upgrade immediately can install JetBrains’ dedicated security patch plugin, which supports TeamCity versions 2017.1 and later.
For instances running TeamCity 2024.03 or newer, security patches can be reviewed through the Administration > Updates interface.
Servers running versions from 2017.1 through 2018.1 will require a restart following plugin installation. At the same time, later releases can enable the plugin without needing to restart.
The patch plugin addresses only CVE-2026-63077, so organizations should still plan for a full upgrade to obtain additional security fixes.
As part of a defense-in-depth strategy, JetBrains recommends restricting access to TeamCity to trusted networks, placing internet-facing deployments behind a VPN or an additional access control layer, running the service with the minimum required privileges, and hosting TeamCity servers separately from build agents.
ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.





