Our takeJetBrains fixed a critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077, CVSS 9.8). Cloud is already patched. Self-hosters: upgrade to 2025.11.7 or 2026.1.3, or apply the security patch plugin. Hosted users can ignore this one.Cyber Resilience desk
Sources (4)
- hackernews · hackernews
- helpnet · helpnet
- hackernews · hackernews
- hackernews · hackernews
What this means for you — Security leader:If you run TeamCity On-Premises, upgrade to 2025.11.7 or 2026.1.3 now, or apply JetBrains’ security patch plugin if you cannot upgrade yet. Cloud instances are already patched; prioritize any internet-exposed servers given unauthenticated RCE at CVSS 9.8.
What this means for you — Lean IT orgs:If you self-host TeamCity, update to 2025.11.7 or 2026.1.3 immediately, or install JetBrains’ patch plugin. If you use TeamCity Cloud, you are already covered and need no action.
What this means for you — MSP:Inventory clients on TeamCity On-Premises and push 2025.11.7/2026.1.3 or the JetBrains security patch plugin, starting with internet-facing instances. TeamCity Cloud tenants are already patched.
What this means for you — Researcher:CVE-2026-63077 is unauthenticated OS command execution (CVSS 9.8) on all TeamCity On-Premises versions; fixed in 2025.11.7 and 2026.1.3, with a JetBrains backport plugin. Watch for probing and exploit attempts against exposed TeamCity management endpoints.