JetBrains Patches CVSS 9.8 TeamCity Flaw Allowing Server Takeover
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-63077 | Unauthenticated Deserialization RCE in JetBrains TeamCity On-Premises CVE-2026-63077 is a critical (CVSS 9.8) unauthenticated remote code execution vulnerability in JetBrains TeamCity, caused by deserialization of untrusted data (CWE-502) in the agent polling protocol. An attacker with network access to the TeamCity server, but no credentials of any kind, can send maliciously crafted serialized input to the agent polling endpoint and execute arbitrary code on the server. Successful exploitation yields full server takeover, exposing source code, build logs, stored secrets and credentials, and providing a pivot point into build agents and connected infrastructure; related headlines describe a real breach in which AWS credentials were extracted from an unpatched TeamCity instance. Organizations running TeamCity On-Premises in versions prior to the fixes (2025.11.7 or 2026.1.3, depending on branch) are affected, while the JetBrains-hosted cloud service is not indicated as impacted. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-08-05, EPSS is 86.5% (100th percentile), and no public PoC is known, meaning defenders cannot rely on public scanners alone and should assume sophisticated attackers are targeting exposed servers. Do: Upgrade immediately to TeamCity 2025.11.7 or 2026.1.3, whichever branch you run; because the flaw is pre-authentication, also hunt for signs of compromise (unexpected builds or agents, new or modified admin users, altered build configurations, and leaked stored credentials/secrets) per vendor guidance, and restrict internet exposure of the TeamCity server until patched. Federal agencies must apply vendor mitigations or discontinue use per CISA BOD 26-04 and the KEV required action, including the Forensics Triage Requirements. | 9.8 | 87% | KEV |
| largetens of thousands of internet-exposed TeamCity on-premises servers (order of magnitude 10k-100k); total on-premises installs likely higher |
Full article323 words · extracted from securityaffairs.com · click to collapse

JetBrains patched a critical TeamCity flaw (CVE-2026-63077) enabling unauthenticated code execution on affected on-premise servers.
JetBrains has released security updates for TeamCity On-Premises after discovering a critical vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8). The flaw could allow unauthenticated attackers to execute arbitrary commands on affected servers. All on-premise versions are impacted, while TeamCity Cloud instances have already been patched. Users are advised to upgrade to versions 2025.11.7 or 2026.1.3.
“A critical security vulnerability has been identified in TeamCity On-Premises and assigned the Common Vulnerabilities and Exposures (CVE) identifier CVE-2026-63077.” reads the advisory. “If exploited, this vulnerability may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands.”
The TeamCity vulnerability affects servers exposed via HTTP(S) and can be exploited without authentication through the agent polling protocol. An attacker could bypass authentication and execute arbitrary OS commands with TeamCity server privileges, potentially accessing sensitive data, credentials, configurations, altering server settings, and compromising CI/CD pipelines. JetBrains recommends restricting network access, applying least-privilege configurations, and running TeamCity on dedicated hosts separated from build agents. No active exploitation has been observed at disclosure time.
The company has also released a security patch plugin for organizations unable to immediately upgrade TeamCity to versions 2025.11.7 or 2026.1.3. The plugin fixes only CVE-2026-63077 and can be installed on TeamCity 2017.1 and later. For newer versions, security patches can be managed directly from the administration console.
“The security patch plugin will address only the vulnerability described above (CVE-2026-63077).” continues the advisory.”We always recommend upgrading your server to the latest version to benefit from many other security updates.”
JetBrains recommends protecting internet-facing TeamCity servers by requiring VPN access or adding extra security controls. Exposing login pages or REST APIs can provide attackers with potential entry points to exploit newly disclosed vulnerabilities.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CVE-2026-63077)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/196169/security/jetbrains-patches-cvss-9-8-teamcity-flaw-allowing-server-takeover.html