INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
TeamCity Remote Code Execution Vulnerability Flaw
| 2026-07-30 22:01 CRITICAL LOW VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The recent discovery of a critical TeamCity flaw, CVE-2026-63077, has raised significant concerns among security experts and administrators. This vulnerability allows for unauthenticated code execution on affected on-premise servers, compromising data, configurations, and build artifacts. JetBrains has released patches to address the issue, but users are advised to upgrade to versions 2025.11.7 or 2026.1.3 as soon as possible. The flaw was privately reported to JetBrains on July 10 and addressed in TeamCity versions 2025.11.7 and 2026.1.3, with a recommended action for customers unable to upgrade to the latest releases being to use the security patch plugin available for customers who cannot upgrade.
Technical Mitigations AI-generated
* Implement least-privilege configurations for TeamCity servers to limit the privileges of server processes and reduce the attack surface.
* Restrict network access to TeamCity servers, especially those exposed via HTTP(S), and consider running them on dedicated hosts separated from build agents.
* Regularly update and patch TeamCity versions to ensure you have the latest security fixes and prevent exploitation of known vulnerabilities like CVE-2026-63077.
* Consider using a Virtual Private Network (VPN) or other protective layers when accessing internet-facing TeamCity servers, as this can provide an additional layer of defense against unauthorized access.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-63077CVE-2026-63077
Target & Sectors
Global Scope
Incident Timeline
2026.1.3
Threat actors exploited a critical TeamCity remote code execution flaw in JetBrains' TeamCity versions 2025.11.7 and 2026.1.3 by using the `System` class to execute arbitrary code.
Click on any entity below to view its context and source!
infrastructure
2025.11.7
Recommended actions
JetBrains says the issue was privately reported to them on July 10 and was addressed in TeamCity versions 2025.11.7 and 2026.1.3.
The company has also released a security patch plugin for organizations unable to immediately upgrade TeamCity to versions 2025.11.7 or 2026.1.3.
infrastructure
2026.1.3
Recommended actions
JetBrains says the issue was privately reported to them on July 10 and was addressed in TeamCity versions 2025.11.7 and 2026.1.3.
The company has also released a security patch plugin for organizations unable to immediately upgrade TeamCity to versions 2025.11.7 or 2026.1.3.
July 10
JetBrains addressed a TeamCity remote code execution flaw in versions 2025.11.7 and 2026.1.3 due to an internally reported issue on July 10.
Click on any entity below to view its context and source!
infrastructure
2025.11.7
Recommended actions
JetBrains says the issue was privately reported to them on July 10 and was addressed in TeamCity versions 2025.11.7 and 2026.1.3.
infrastructure
2026.1.3
Recommended actions
JetBrains says the issue was privately reported to them on July 10 and was addressed in TeamCity versions 2025.11.7 and 2026.1.3.
July 27
Threat actors exploited a critical TeamCity vulnerability to target JetBrains systems.
2017.1+
Threat actors exploited a remote code execution vulnerability in JetBrains TeamCity 2017.1 to gain unauthorized access and control of affected systems.
Click on any entity below to view its context and source!
infrastructure
2017.1
A security patch is available for TeamCity 2017.1+ as a plugin for customers unable to upgrade to the latest releases.
2026/07/30
Threat actors used a security vulnerability in JetBrains' TeamCity On-Premises to bypass authentication and execute arbitrary OS commands.
Click on any entity below to view its context and source!
organisation
JetBrains
JetBrains warns of critical TeamCity remote code execution flaw.
JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover
JetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers.
organisation
TeamCity On-Premises
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution.
JetBrains has released security updates for TeamCity On-Premises after discovering a critical vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8).
organisation
CVE-2026-63077
JetBrains has released security updates for TeamCity On-Premises after discovering a critical vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8).
infrastructure
9.8
JetBrains has released security updates for TeamCity On-Premises after discovering a critical vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8).
organisation
HTTPS
The security issue is tracked as CVE-2026-63077 and can be leveraged by an attacker with HTTPS access to a TeamCity server to bypass authentication via the agent polling protocol and execute arbitrary operating system commands with the privileges of the server process.
organisation
the Common
“A critical security vulnerability has been identified in TeamCity On-Premises and assigned the Common Vulnerabilities and Exposures (CVE) identifier CVE-2026-63077.” reads the
advisory
.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, CVE-2026-63077)
infrastructure
2025.11.7
Users are advised to upgrade to versions
2025.11.7 or 2026.1.3
.
infrastructure
2026.1.3
Users are advised to upgrade to versions
2025.11.7 or 2026.1.3
.
infrastructure
2017.1
Also, TeamCity versions 2017.1 through 2018.1 will require a server restart for the security updates to take effect after installing the patch plugin.
infrastructure
2018.1
Also, TeamCity versions 2017.1 through 2018.1 will require a server restart for the security updates to take effect after installing the patch plugin.
organisation
TeamCity
TeamCity is a commercial continuous integration and continuous delivery (CI/CD) server that is used for building, testing, and deploying software.
An attacker could bypass authentication and execute arbitrary OS commands with TeamCity server privileges, potentially accessing sensitive data, credentials, configurations, altering server settings, and compromising CI/CD pipelines.
organisation
CI
TeamCity is a commercial continuous integration and continuous delivery (CI/CD) server that is used for building, testing, and deploying software.
An attacker could bypass authentication and execute arbitrary OS commands with TeamCity server privileges, potentially accessing sensitive data, credentials, configurations, altering server settings, and compromising CI/CD pipelines.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
JetBrains Patches Critical
JetBrains Patches Critical TeamCity Flaw
Tactical Metrics
Metrics
infrastructure
2025.11.7
Software Version
Click for context!
Recommended actions
JetBrains says the issue was privately reported to them on July 10 and was addressed in TeamCity versions 2025.11.7 and 2026.1.3.
Users are advised to upgrade to versions
2025.11.7 or 2026.1.3
.
The company has also released a security patch plugin for organizations unable to immediately upgrade TeamCity to versions 2025.11.7 or 2026.1.3.
Metrics
infrastructure
2026.1.3
Software Version
Recommended actions
JetBrains says the issue was privately reported to them on July 10 and was addressed in TeamCity versions 2025.11.7 and 2026.1.3.
Users are advised to upgrade to versions
2025.11.7 or 2026.1.3
.
The company has also released a security patch plugin for organizations unable to immediately upgrade TeamCity to versions 2025.11.7 or 2026.1.3.
Metrics
infrastructure
2017.1
Software Version
A security patch is available for TeamCity 2017.1+ as a plugin for customers unable to upgrade to the latest releases.
Also, TeamCity versions 2017.1 through 2018.1 will require a server restart for the security updates to take effect after installing the patch plugin.
Metrics
infrastructure
2018.1
Software Version
Also, TeamCity versions 2017.1 through 2018.1 will require a server restart for the security updates to take effect after installing the patch plugin.
Metrics
infrastructure
9.8
Software Version
JetBrains has released security updates for TeamCity On-Premises after discovering a critical vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8).
Intelligence Sources
BleepingComputer
2026-07-30
JetBrains warns of critical TeamCity remote code execution flaw
BleepingComputer
Security Affairs
2026-07-28
JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover
Security Affairs
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-31T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
10x
organisation
Identified Entity
JetBrains
entity
5x
infrastructure
Software Version
2025.11.7
version
4x
timeline
Temporal Reference
July 10
date
2x
tactic
Cyber Operation Type
Ransomware
tactic
2x
general metric
%
54
%
2x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
Contextual Telemetry
Context Block
4 METRICS
vulnerability
Exploited CVE
CVE-2026-63077
cve
general metric
Teamcity Versions
2,017
teamcity versions
general metric
Teamcity
2,024
teamcity
vulnerability
CVSS Score
10
score
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.