Critical Code Execution Vulnerability Patched in TeamCity
Summary
A critical code execution vulnerability, tracked as CVE-2026-63077, has been patched in TeamCity. The vulnerability could be exploited without authentication through the agent polling protocol.
IFF Assessment
The vulnerability allows for unauthenticated code execution, posing a significant risk to systems and data.
Severity
The vulnerability allows for unauthenticated remote code execution, which is a critical severity. The CVSS score is estimated to be high due to the potential for widespread impact and ease of exploitation.
Defender Context
This critical vulnerability in TeamCity highlights the importance of prompt patching for CI/CD tools, which often have privileged access. Defenders should prioritize updates for such systems and monitor for any indicators of compromise related to this CVE.