Security · 1d ago
Critical TeamCity Flaw Allows Remote Code Execution Without Authentication
JetBrains disclosed a critical vulnerability (CVE-2026-63077, CVSS 9.8) in on-premise TeamCity versions that could let attackers execute OS commands without logging in. The flaw affects all on-premise versions and is fixed in versions 2025.11.7 and 2026.1.3. Cloud instances were already patched.
Meridian48 take
This is a severe, unauthenticated RCE in a widely used CI/CD tool, making it a prime target for supply-chain attacks.
Read the full reporting
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In →
The Hacker News
teamcityremote-code-execution