Teamcity
This hub aggregates every CVE we track for Teamcity, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
275
CVEs tracked
18
Critical
41
High
3
In CISA KEV
Severity distribution
MEDIUM186HIGH41LOW30CRITICAL18
Monthly trend
5
0
5
0
9
3
2
3
3
4
5
11
3
3
0
0
11
0
3
0
0
12
0
6
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Teamcity.
- CVE-2026-65907In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible9.1
- CVE-2026-65906In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible8.8
- CVE-2026-59796In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks8.1
- CVE-2026-59795In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible8.1
- CVE-2026-59794In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data7.3
- CVE-2026-59793In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration8.8
- CVE-2026-49381In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible3.4
- CVE-2026-49380In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible3.1
- CVE-2026-49379In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names6.5
- CVE-2026-49377In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters4.3
- CVE-2026-49378In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion4.3
- CVE-2026-49376In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin6.5
- CVE-2026-49375In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page6.1
- CVE-2026-49373In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings7.1
- CVE-2026-49374In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters7.6
Product normalization is registry-driven with AI assist and human review. How it works