JetBrains says a crafted HTTP request could break TeamCity

Summary

JetBrains has disclosed a critical vulnerability in its TeamCity DevOps platform, identified as CVE-2026-63077, which allows unauthenticated attackers to execute arbitrary operating system commands. The flaw affects TeamCity On-Premises deployments and has been patched in recent versions, with a security patch plugin available for those unable to upgrade immediately.

IFF Assessment

FOE

This vulnerability allows unauthenticated attackers to execute arbitrary commands, posing a significant threat to systems and data.

Severity

9.8 Critical

Defender Context

Defenders should prioritize patching TeamCity On-Premises deployments immediately to mitigate the risk of unauthenticated RCE. Monitoring for any signs of exploitation targeting the agent polling protocol is crucial, especially for internet-exposed instances.

Read Full Story →