CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
JetBrains has addressed a critical remote code execution vulnerability, CVE-2026-63077, impacting all versions of TeamCity On-Premises. The flaw allows unauthenticated attackers to execute arbitrary commands on the server through the agent polling protocol. With a CVSS score of 9.8, this high-severity issue could lead to full system compromise and exposure of sensitive credentials. Affected organizations are urged to update to TeamCity 2025.11.7 or 2026.1.3 immediately. Alternatively, a security patch plugin is available for older versions starting from 2017.1. Cloud users are unaffected.
Overview
On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077">CVE-2026-63077, a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8. An unauthenticated remote attacker with HTTP(S) access to a TeamCity server can exploit the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.…