← Back to Feed

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

CVE-2026-63077

July 28, 2026 · The Hacker News · Severity: CRITICAL

JetBrains patched CVE-2026-63077 (CVSS 9.8) in TeamCity On-Premises, an unauthenticated remote code execution vulnerability exploitable via the agent polling protocol. All on-premises versions are affected, with fixes in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances were automatically updated by JetBrains.

Key Takeaways

  • CVE-2026-63077 (CVSS 9.8) is an unauthenticated RCE vulnerability in all TeamCity On-Premises versions
  • The flaw allows bypassing authentication checks via the agent polling protocol to execute OS commands
  • JetBrains credited Antoni Tremblay for discovering and reporting the flaw on July 10, 2026
☕ Buy a Coffee