Exploits

TeamCity RCE Vulnerability: Critical Update Required Now

Published  ·  7 min read

If you are running an on-premises version of JetBrains TeamCity, you have a critical update to apply. A security vulnerability has been discovered that could allow an unauthenticated attacker to execute arbitrary code on your build server.

The flaw, tracked as CVE-2026-63077, carries a CVSS score of 9.8. That is just shy of maximum severity, and it affects all on-premises TeamCity versions. JetBrains has released patches, and The Hacker News has been covering the story as it develops.

Antoni Tremblay discovered and reported the flaw on July 10, 2026. JetBrains credited the researcher for finding the vulnerability and has now released fixes. Let me walk you through everything you need to know about this TeamCity vulnerability and what you need to do about it.

Description of CVE-2026-63077 TeamCity Vulnerability

TeamCity Vulnerability is an authentication bypass which results in Remote Code Execution. An attacker who has HTTP/HTTPS access to the TeamCity Server is able to bypass the authentication and execute OS commands under the privileges of the TeamCity Server process.

That is a serious problem. TeamCity is a build management and continuous integration server. It is often at the heart of an organization's development pipeline. In case attackers have control over executing commands on the TeamCity server, then it is possible that source code, credentials, builds can be manipulated, as well as the entire software delivery process.

The particular vector through which this vulnerability can be exploited in TeamCity is through the agent polling protocol. Attackers can exploit this protocol to sidestep authentication checks and achieve command execution. JetBrains did not provide exhaustive technical details, but the impact is clear.

Impact of this TeamCity Vulnerability

As with other security issues, the effect of exploitation of this TeamCity Vulnerability will depend upon what privileges have been given to the TeamCity Server process but there could be some pretty serious consequences.

A successful compromise can lead to:

  • Exposure of TeamCity data, configurations, and stored credentials
  • Modification of server state
  • Access to build artifacts and source code
  • Potential compromise of downstream systems

For organizations that use TeamCity as a critical part of their software delivery pipeline, this TeamCity vulnerability represents a significant risk. Attackers could inject malicious code into builds, steal proprietary source code, or use the server as a foothold to pivot into other parts of the network.

Which versions are affected?

All on-premises TeamCity versions are impacted by the TeamCity vulnerability. JetBrains has fixed the issue with versions 2025.11.7 and 2026.1.3. As an additional safeguard, all TeamCity Cloud instances were also upgraded, and cloud customers don’t need to act on this security advisory.

If you run any version before 2025.11.7 or 2026.1.3 of TeamCity on-premises, you’re vulnerable to the TeamCity vulnerability, and you must upgrade your system immediately.

Has This TeamCity Vulnerability Been Exploited?

Here is the good news. JetBrains stated there is no evidence to indicate that this TeamCity vulnerability has been exploited in the wild. That does not mean it is safe to ignore. History tells us that once a patch is released and details become public, attackers start analyzing the fix and developing exploits.
The responsible thing to do is patch now, before the threat materializes.

What Should You Do About This TeamCity Vulnerability?

The best thing to do is upgrade to version 2025.11.7 or 2026.1.3 right away because those versions have a patch for the TeamCity vulnerability.

JetBrains understands that updating a critical build server is not always instant. For customers who are unable to apply an update, the company has released a security patch plugin for versions 2017.1 and later. This plugin addresses only the specific TeamCity vulnerability described above. It does not include other security updates.

" We always recommend upgrading your server to the latest version to benefit from many other security updates, " JetBrains cautioned.

Best Practices Beyond the Patch

JetBrains also provided broader security guidance that goes beyond just patching this TeamCity vulnerability. Customers should consider requiring VPN connections or implementing an extra layer of security to prevent unauthorized access to internet-facing TeamCity servers.

The company specifically warned: " Even exposing the TeamCity login screen or REST API can provide attackers with potential entry points to exploit newly disclosed vulnerabilities. "

This is a broader principle that applies to all CI/CD infrastructure. Build servers are often exposed to the internet for legitimate reasons, but they are also high-value targets. If an attacker can reach your TeamCity server, they can potentially find ways to exploit it.

The History of TeamCity Vulnerabilities

This TeamCity vulnerability is not the first time JetBrains has had to patch a critical issue. TeamCity has been a target for attackers because of its position in the development pipeline. Compromising a build server is a direct path to compromising software supply chains.

Previous TeamCity vulnerabilities have been exploited in the wild. Attackers have used them to gain initial access to corporate networks, steal source code, and implant backdoors in build artifacts. The pattern is clear: attackers are interested in CI/CD infrastructure, and they will use vulnerabilities to get in.

What This Means for Your Organization

If you are using TeamCity on-premises, this TeamCity vulnerability is a reminder to review your security posture around build infrastructure. Patching is the first step, but it should not be the only step.

Ask yourself the following questions:

  • Can your TeamCity server be accessed via the internet?
  • Have you implemented any system to monitor any unauthorized access?
  • Are your credentials stored securely in the TeamCity?
  • Have you got any strategy to apply critical security patches rapidly?

This vulnerability in TeamCity demonstrates the importance of doing a proper assessment of the security of your CI/CD pipeline. The build server is a critical component of infrastructure, which should receive the same care as any other critical infrastructure component.

Conclusion

This TeamCity vulnerability CVE-2026-63077 is an important one to address right away. Unauthenticated remote code execution on a build server is about as bad as it gets. The patch is available, and there is no excuse to delay.

JetBrains has done the right thing by releasing patches and a security patch plugin for older versions. Cloud customers are already covered. On-premises customers need to act.

Check your TeamCity version. If you are not running 2025.11.7 or 2026.1.3, update now. If you cannot update immediately, apply the security patch plugin.  It’s worth taking a look at your CI/CD security in general too.

The TeamCity vulnerability has not been exploited yet. But the window of opportunity for attackers is opening. Do not be the one who waits too long.

FAQ Section

What is the TeamCity vulnerability CVE-2026-63077?

This is an important vulnerability in JetBrains TeamCity that enables attackers to gain remote code execution without needing to authenticate. The attacker can simply use HTTP/HTTPS to execute arbitrary commands with the same privileges as that of the TeamCity server process.

Which TeamCity versions are affected by this vulnerability?

All on-premises TeamCity versions are affected. JetBrains has fixed the issue in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already been updated.

Has the TeamCity vulnerability been exploited in the wild?

JetBrains stated there is no evidence of exploitation in the wild at this time. However, it is critical to patch now before attackers develop working exploits.

How can one solve the issue related to TeamCity exploit in case an upgrade is impossible?

The JetBrains team created a security patch plug-in for TeamCity 2017.1 and above. Nonetheless, the plug-in only solves the problem of CVE-2026-63077, and the JetBrains company recommends updating TeamCity for additional security patches.

What further security steps should I implement to enhance the security of TeamCity?

The suggestion by JetBrains is that one should limit the access to TeamCity servers through VPNs or any other extra layer of security. Just making the login page or REST API available may serve as an entry point for the future.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067