INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

TeamCity Remote Code Execution Vulnerability Flaw

| 2026-07-30 22:01 CRITICAL LOW VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The recent discovery of a critical TeamCity flaw, CVE-2026-63077, has raised significant concerns among security experts and administrators. This vulnerability allows for unauthenticated code execution on affected on-premise servers, compromising data, configurations, and build artifacts. JetBrains has released patches to address the issue, but users are advised to upgrade to versions 2025.11.7 or 2026.1.3 as soon as possible. The flaw was privately reported to JetBrains on July 10 and addressed in TeamCity versions 2025.11.7 and 2026.1.3, with a recommended action for customers unable to upgrade to the latest releases being to use the security patch plugin available for customers who cannot upgrade.
Technical Mitigations AI-generated
* Implement least-privilege configurations for TeamCity servers to limit the privileges of server processes and reduce the attack surface. * Restrict network access to TeamCity servers, especially those exposed via HTTP(S), and consider running them on dedicated hosts separated from build agents. * Regularly update and patch TeamCity versions to ensure you have the latest security fixes and prevent exploitation of known vulnerabilities like CVE-2026-63077. * Consider using a Virtual Private Network (VPN) or other protective layers when accessing internet-facing TeamCity servers, as this can provide an additional layer of defense against unauthorized access.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-63077CVE-2026-63077
Target & Sectors
Global Scope
Incident Timeline
‎2026.1.3
Threat actors exploited a critical TeamCity remote code execution flaw in JetBrains' TeamCity versions 2025.11.7 and 2026.1.3 by using the `System` class to execute arbitrary code.
infrastructure 2025.11.7
infrastructure 2026.1.3
‎July 10
JetBrains addressed a TeamCity remote code execution flaw in versions 2025.11.7 and 2026.1.3 due to an internally reported issue on July 10.
infrastructure 2025.11.7
infrastructure 2026.1.3
‎July 27
Threat actors exploited a critical TeamCity vulnerability to target JetBrains systems.
‎2017.1+
Threat actors exploited a remote code execution vulnerability in JetBrains TeamCity 2017.1 to gain unauthorized access and control of affected systems.
infrastructure 2017.1
‎2026/07/30
Threat actors used a security vulnerability in JetBrains' TeamCity On-Premises to bypass authentication and execute arbitrary OS commands.
organisation JetBrains
organisation TeamCity On-Premises
organisation CVE-2026-63077
infrastructure 9.8
organisation HTTPS
organisation the Common
organisation SecurityAffairs
infrastructure 2025.11.7
infrastructure 2026.1.3
infrastructure 2017.1
infrastructure 2018.1
organisation TeamCity
organisation CI
organisation EDR
organisation JetBrains Patches Critical
Tactical Metrics
Metrics
infrastructure
‎2025.11.7
Software Version
Metrics
infrastructure
‎2026.1.3
Software Version
Metrics
infrastructure
‎2017.1
Software Version
Metrics
infrastructure
‎2018.1
Software Version
Metrics
infrastructure
‎9.8
Software Version
Intelligence Sources
BleepingComputer 2026-07-30
Security Affairs 2026-07-28