Unauthenticated Remote Code Execution Possible
A severe security flaw has been found in JetBrains TeamCity On-Premise software. This vulnerability allows attackers to run commands on affected systems without needing to log in. JetBrains is strongly advising all users of the on-premise versions to update their software immediately to prevent potential attacks.
Breaking news
Judge Questions Fairness of Google's AI Overviews in Antitrust Case
Apple's iPhone Event Tagline Varies by Country Ahead of September Launch
Gemini 3.5 Transcribe Eliminates Filler Words From Speech
Google addresses Keep list addition issues with potential fixThe flaw, identified as CVE-2026-63077, carries a critical CVSS score of 9.8. This high score indicates a significant risk. All versions of TeamCity On-Premise are susceptible to this issue.
How Can Organizations Protect Themselves?
This vulnerability could lead to arbitrary code execution. An attacker could take full control of the server. They would not need any login credentials to exploit this weakness. This makes the flaw particularly dangerous for organizations using the affected software.
The security issue impacts the integrity and availability of the system. Data could be compromised or destroyed. Business operations might face severe disruptions.
# What is the main risk of this vulnerability?
JetBrains has released patches to address this critical vulnerability. Updating to the latest version of TeamCity On-Premise is the only way to secure systems. Organizations should prioritize this update to safeguard their infrastructure. Delaying the update could expose systems to significant risks from malicious actors.
# Which versions of TeamCity are affected?
Failure to update could result in unauthorized access to sensitive data. It could also lead to the installation of malware. Companies must act quickly to mitigate these threats.
The primary risk is unauthenticated remote code execution. This means an attacker can run commands on your server without needing a password, potentially taking full control of the system.
# What action should users take immediately?
All on-premise versions of JetBrains TeamCity are affected by this critical security flaw. Cloud versions are not mentioned as being impacted.
Users of TeamCity On-Premise should update their software to the latest available version as soon as possible. This update includes the necessary security patches to fix the vulnerability.