JetBrains Urges Immediate Patching for Critical TeamCity On-Premises Security Flaw

Context mode is active. Hover over any highlighted term to see its definition. Click a nested term to go deeper.
JetBrains has issued an urgent warning to users of its TeamCity On-Premises software, advising them to immediately patch a critical security vulnerability, identified as CVE-2026-63077. This flaw is an "unauthenticated remote code execution" (RCE) vulnerability, meaning attackers could take full control of affected servers without needing any login details. Discovered privately on July 10, 2026, by researcher Antoni Tremblay, the bug carries a severe CVSS score of 9.8, underscoring the high risk it poses. At the heart of the problem is insecure deserialization of untrusted data within TeamCity's agent polling protocol, a key communication channel. Exploitation allows an attacker with network access to bypass authentication and execute arbitrary commands with the server's privileges, which can expose sensitive data, stored credentials, and compromise entire software supply chain. While JetBrains has confirmed no active exploitation of this particular flaw at the time of its advisory, cybersecurity experts like Rapid7 highlight that similar critical TeamCity vulnerabilities have been weaponized rapidly by state-backed groups and ransomware gangs in the past, often within days of public disclosure. JetBrains strongly recommends that all TeamCity On-Premises users upgrade to versions 2025.11.7 or 2026.1.3 without delay. For those unable to perform a full upgrade, a security patch plugin is available for older versions (2017.1+), specifically addressing CVE-2026-63077. Additionally, restricting network access to TeamCity servers and running them with minimum operating system privileges are crucial defense-in-depth measures. TeamCity Cloud users are unaffected, as JetBrains has already implemented the necessary fixes on its hosted platform.