Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

The Critical TeamCity Vulnerability: A Security Alert for Organizations




U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog, categorizing it as a high-severity vulnerability (CVSS score of 9.8). The identified bug allows attackers to bypass authentication checks and execute arbitrary operating system commands. Organizations are advised to upgrade their TeamCity versions to mitigate the risk associated with this vulnerability.

  • JetBrains TeamCity has a critical vulnerability (CVE-2026-63077) with a CVSS score of 9.8, allowing unauthenticated attackers to execute arbitrary commands.
  • The vulnerability affects on-premise versions of TeamCity and can be exploited through the agent polling protocol.
  • Upgrades to version 2025.11.7 or 2026.1.3 are recommended for organizations using TeamCity On-Premises.
  • Additional mitigation measures include restricting network access, applying least-privilege configurations, and running TeamCity on dedicated hosts.
  • A security patch plugin is available for organizations unable to upgrade immediately.



  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added a critical vulnerability in JetBrains TeamCity to its Known Exploited Vulnerabilities catalog. The identified vulnerability, tracked as CVE-2026-63077, is classified under the Common Vulnerabilities and Exposures (CVE) system with a CVSS score of 9.8. This high-severity vulnerability poses significant risks to organizations that use TeamCity On-Premises, allowing unauthenticated attackers to execute arbitrary commands on affected servers.

    The flaw was discovered by JetBrains at the end of July, and the company has since released security updates for TeamCity On-Premises after discovering this critical vulnerability. The vulnerabilities are primarily found in all on-premise versions of TeamCity, with TeamCity Cloud instances having already been patched. Therefore, organizations using TeamCity On-Premises need to upgrade to versions 2025.11.7 or 2026.1.3 as soon as possible.

    The identified vulnerability affects servers that are exposed via HTTP(S) and can be exploited without authentication through the agent polling protocol. An attacker could bypass authentication and execute arbitrary OS commands with TeamCity server privileges, potentially accessing sensitive data, credentials, configurations, altering server settings, and compromising CI/CD pipelines.

    In order to mitigate this risk, JetBrains recommends restricting network access, applying least-privilege configurations, and running TeamCity on dedicated hosts separated from build agents. Additionally, the company has released a security patch plugin for organizations unable to immediately upgrade TeamCity to versions 2025.11.7 or 2026.1.3. This plugin fixes only CVE-2026-63077 and can be installed on TeamCity 2017.1 and later.

    Furthermore, experts advise private organizations to review the Known Exploited Vulnerabilities catalog and address vulnerabilities in their infrastructure. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to fix this vulnerability by August 8, 2026. As always, it is essential for all organizations to stay informed about newly disclosed vulnerabilities and implement adequate security measures.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/The-Critical-TeamCity-Vulnerability-A-Security-Alert-for-Organizations-ehn.shtml

  • https://securityaffairs.com/196725/security/u-s-cisa-adds-a-jetbrains-teamcity-flaw-to-its-known-exploited-vulnerabilities-catalog.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-63077

  • https://www.cvedetails.com/cve/CVE-2026-63077/


  • Published: Thu Aug 6 04:13:37 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us