Tag

Cve 2026 63077

All articles tagged with #cve 2026 63077

JetBrains flags critical TeamCity RCE via auth bypass (CVE-2026-63077)
security1 hour ago

JetBrains flags critical TeamCity RCE via auth bypass (CVE-2026-63077)

JetBrains warns that TeamCity On-Premises is vulnerable to a critical authentication bypass vulnerability (CVE-2026-63077) that could enable remote code execution via the agent polling protocol. All On-Prem versions are affected; Cloud customers are protected. Mitigations include upgrading to TeamCity 2025.11.7 or 2026.1.3, or applying the patch plugin for older releases (with restart required for 2017.1–2018.1). TeamCity 2024.03+ auto-downloads patches. Follow best practices to limit exposure (VPN/private networks) since exposing login pages or REST APIs can give attackers entry. No active exploitation reported as of the advisory, but prompt remediation is advised.