Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
28 July 2026
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution.
The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already