← Back to Feed
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
CVE-2026-63077
July 28, 2026 · The Hacker News · Severity: CRITICAL
JetBrains patched CVE-2026-63077 (CVSS 9.8) in TeamCity On-Premises, an unauthenticated remote code execution vulnerability exploitable via the agent polling protocol. All on-premises versions are affected, with fixes in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances were automatically updated by JetBrains.
Key Takeaways
- CVE-2026-63077 (CVSS 9.8) is an unauthenticated RCE vulnerability in all TeamCity On-Premises versions
- The flaw allows bypassing authentication checks via the agent polling protocol to execute OS commands
- JetBrains credited Antoni Tremblay for discovering and reporting the flaw on July 10, 2026