JetBrains says a crafted HTTP request could break TeamCity
Summary
JetBrains has disclosed a critical vulnerability in its TeamCity DevOps platform, identified as CVE-2026-63077, which allows unauthenticated attackers to execute arbitrary operating system commands. The flaw affects TeamCity On-Premises deployments and has been patched in recent versions, with a security patch plugin available for those unable to upgrade immediately.
IFF Assessment
This vulnerability allows unauthenticated attackers to execute arbitrary commands, posing a significant threat to systems and data.
Severity
Defender Context
Defenders should prioritize patching TeamCity On-Premises deployments immediately to mitigate the risk of unauthenticated RCE. Monitoring for any signs of exploitation targeting the agent polling protocol is crucial, especially for internet-exposed instances.