Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical JetBrains TeamCity CVE-2024-27198 Remote Code Execution Flaw Patched
July 31, 2026
FBI Warns North Korean IT Workers Exploit Stolen Identities
July 31, 2026
Google AI Agents Find and Fix 1,072 Chrome Vulnerabilities
July 31, 2026
Home/CyberSecurity News/Critical JetBrains TeamCity CVE-2024-27198 Remote Code Execution Flaw Patched
CyberSecurity News

Critical JetBrains TeamCity CVE-2024-27198 Remote Code Execution Flaw Patched

Key Takeaways A critical remote code execution (RCE) vulnerability, CVE-2026-63077, has been discovered in JetBrains TeamCity On-Premises. The flaw allows unauthenticated attackers with network...

Sarah simpson
Sarah simpson
July 31, 2026 3 Min Read
2 0

Key Takeaways

  • A critical remote code execution (RCE) vulnerability, CVE-2026-63077, has been discovered in JetBrains TeamCity On-Premises.
  • The flaw allows unauthenticated attackers with network access to execute arbitrary commands on the server.
  • All versions of TeamCity On-Premises are affected, posing significant risk to CI/CD pipelines.
  • Patches are available in versions 2025.11.7 and 2026.1.3, along with a security patch plugin for older versions.

JetBrains has disclosed a severe security vulnerability impacting its TeamCity On-Premises continuous integration/continuous delivery (CI/CD) server. Identified as CVE-2026-63077, this critical flaw could enable remote attackers to bypass authentication mechanisms and execute arbitrary commands on affected servers.

Table Of Content

  • Key Takeaways
  • JetBrains Vulnerability Details
  • Remediation and Patches
  • What You Should Do

The vulnerability poses a substantial threat to organizations utilizing TeamCity for their software development workflows. Any TeamCity On-Premises server is susceptible if an attacker has HTTP or HTTPS network access, regardless of whether they possess valid credentials or prior access to the system.

According to JetBrains, the root cause of the issue lies within the TeamCity agent polling protocol. Exploiting this protocol allows an unauthenticated remote attacker to circumvent security checks and execute operating system commands with the same privileges as the TeamCity server process itself.

Such unauthorized access presents profound risks. A successful compromise could expose sensitive data such as stored credentials, configuration files, build artifacts, and project secrets. Furthermore, attackers could manipulate build settings, inject malicious code into software releases, or alter development pipelines, potentially leading to supply chain attacks.

JetBrains Vulnerability Details

The flaw was privately reported to JetBrains on July 10, 2026, by security researcher Antoni Tremblay, who followed the company’s coordinated disclosure process. JetBrains subsequently assigned the identifier CVE-2026-63077 to this critical vulnerability.

Remediation and Patches

JetBrains has released patches for the vulnerability in TeamCity versions 2025.11.7 and 2026.1.3. Administrators are strongly advised to upgrade their installations to one of these patched versions immediately, either by downloading them directly or utilizing the built-in automatic update feature where available.

For organizations unable to perform a full version upgrade immediately, JetBrains offers a dedicated security patch plugin. This plugin specifically addresses CVE-2026-63077 and is compatible with TeamCity versions 2017.1 and later. While the plugin provides an immediate fix, JetBrains stresses that it should be considered a temporary measure, as a full version upgrade incorporates additional important security enhancements.

TeamCity versions 2024.03 and newer can automatically download available security patch plugins and notify administrators if notifications are enabled. Security updates can be reviewed through the Administration menu under “Updates” and “Available Security Updates.”

It is important for administrators to note that TeamCity servers running versions 2017.1 through 2018.1 will require a server restart after the plugin installation. Conversely, installations of TeamCity version 2018.2 and later can enable the patch plugin without needing a server reboot.

JetBrains has confirmed that its TeamCity Cloud customers are not required to take any action. The company has already implemented necessary protections in its cloud infrastructure and has found no evidence of this particular flaw being exploited in TeamCity Cloud instances.

As of the official announcement, JetBrains stated it was unaware of any active exploitation of CVE-2026-63077 in the wild. However, the potential for unauthenticated remote code execution makes swift remediation imperative for all On-Premises deployments.

What You Should Do

  • Upgrade Immediately: Update TeamCity On-Premises to versions 2025.11.7 or 2026.1.3 without delay.
  • Install Security Patch Plugin: If immediate upgrade is not feasible, install the dedicated security patch plugin for CVE-2026-63077, available for versions 2017.1 and later. Remember this is a temporary solution.
  • Restrict Network Access: Limit TeamCity server access to trusted internal networks only.
  • Implement Access Controls: Place any internet-facing TeamCity instances behind a VPN or other robust access control layers.
  • Apply Principle of Least Privilege: Ensure the TeamCity service runs with the absolute minimum necessary operating system privileges.
  • Isolate Build Agents: Consider hosting TeamCity servers separately from build agents to contain the potential impact of a compromise.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

FBI Warns North Korean IT Workers Exploit Stolen Identities

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New SSH Bot Profiles Linux Systems Before Deploying Crypto Miner
July 31, 2026
DeepSeek-Powered Hermes Agent Autonomous Cyberattacks Target Exposed Servers
July 31, 2026
ShutterGap Flaw Exposes AWS Resources Between Security Scans
July 31, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us