JetBrains flags critical TeamCity RCE via auth bypass (CVE-2026-63077)

JetBrains warns that TeamCity On-Premises is vulnerable to a critical authentication bypass vulnerability (CVE-2026-63077) that could enable remote code execution via the agent polling protocol. All On-Prem versions are affected; Cloud customers are protected. Mitigations include upgrading to TeamCity 2025.11.7 or 2026.1.3, or applying the patch plugin for older releases (with restart required for 2017.1–2018.1). TeamCity 2024.03+ auto-downloads patches. Follow best practices to limit exposure (VPN/private networks) since exposing login pages or REST APIs can give attackers entry. No active exploitation reported as of the advisory, but prompt remediation is advised.
- JetBrains warns of critical TeamCity remote code execution flaw BleepingComputer
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In The Hacker News
- Critical Code Execution Vulnerability Patched in TeamCity SecurityWeek
- TeamCity On-Premises RCE Flaw (CVE-2026-63077) Patched The Cyber Express
- JetBrains says a crafted HTTP request could break TeamCity csoonline.com
Reading Insights
1
6
3 min
vs 4 min read
86%
632 → 91 words
Want the full story? Read the original article
Read on BleepingComputer