Critical Code Execution Vulnerability Patched in TeamCity
What happened
JetBrains patched a critical unauthenticated remote code execution vulnerability (CVE-2026-63077) in TeamCity. The flaw is exploitable via the agent polling protocol, allowing attackers to execute arbitrary code on the server.
Why it ranks #1
Confirmed critical RCE with an authentication bypass in a widely used enterprise CI/CD tool represents the highest immediate risk of exploitation and enterprise exposure.
Who should care
Application security teams, IT and platform operations, SOC and incident response teams
What to do
Apply the JetBrains security update for TeamCity immediately.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- disclosed