Critical Code Execution Vulnerability Patched in TeamCity

Summary

A critical code execution vulnerability, tracked as CVE-2026-63077, has been patched in TeamCity. The vulnerability could be exploited without authentication through the agent polling protocol.

IFF Assessment

FOE

The vulnerability allows for unauthenticated code execution, posing a significant risk to systems and data.

Severity

9.8 Critical

Defender Context

This critical vulnerability in TeamCity highlights the importance of prompt patching for CI/CD tools, which often have privileged access. Defenders should prioritize updates for such systems and monitor for any indicators of compromise related to this CVE.

Read Full Story →