CVE Tools
Back to feed
Patch released JetBrains TeamCity rce JetBrains cloud

CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

Rapid7 Blog·By Rapid7··1 min read
CVE Tools coverage

JetBrains has addressed a critical remote code execution vulnerability, CVE-2026-63077, impacting all versions of TeamCity On-Premises. The flaw allows unauthenticated attackers to execute arbitrary commands on the server through the agent polling protocol. With a CVSS score of 9.8, this high-severity issue could lead to full system compromise and exposure of sensitive credentials. Affected organizations are urged to update to TeamCity 2025.11.7 or 2026.1.3 immediately. Alternatively, a security patch plugin is available for older versions starting from 2017.1. Cloud users are unaffected.

Overview

On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077">CVE-2026-63077, a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8. An unauthenticated remote attacker with HTTP(S) access to a TeamCity server can exploit the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.…

Continue reading on Rapid7 Blog