TeamCity 9.8 RCE Flaw Hits All On-Prem Versions
JetBrains has patched CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in all TeamCity On-Premises versions. Update to 2025.11.7 or 2026.1.3 now.
JetBrains has patched CVE-2026-63077 — a CVSS 9.8 unauthenticated remote code execution flaw that affects every on-premises version of TeamCity. No account required to trigger it. The patch is out now.
TeamCity Cloud is already fixed. On-premises customers need to act.
What changed
Two fixed releases are available:
- 2025.11.7 — for customers on the 2025.11.x LTS branch
- 2026.1.3 — for customers on the current 2026.1.x branch
JetBrains publishes confirmed security issue details at jetbrains.com/privacy-security/issues-fixed/. The NVD record for CVE-2026-63077 is confirmed at CVSS 9.8 critical.
The flaw allows an unauthenticated remote attacker to execute operating system commands on the server running TeamCity. No further technical breakdown of the exploitation path beyond what’s in the advisory — if you want the full picture, start there.
Why build servers specifically
Build infrastructure holds source code, deploy keys, signing certificates, and pipeline credentials for every system that pipeline touches. A compromised CI server isn’t just a compromised server — it’s a privilege escalation vector into your entire delivery chain.
TeamCity on-premises is common in enterprises that haven’t moved CI to cloud-hosted infrastructure. If yours is reachable over the network — even behind layered controls — a CVSS 9.8 no-auth RCE changes the risk calculus for everything downstream of it.
No active exploitation confirmed at time of writing. CISA has not added CVE-2026-63077 to the Known Exploited Vulnerabilities catalog. The honest timeline: that status won’t last indefinitely for a critical, widely-deployed target with a public advisory.
Patch priority
- Check your version: Administration → Server Administration → License & Product Info.
- Upgrade to 2025.11.7 or 2026.1.3. Both are available on the JetBrains download page.
- If patching is delayed: restrict network access to the TeamCity port to known-good CIDRs. Not a fix — a containment measure while you schedule the update.
- TeamCity Cloud: already mitigated, no action required.
Patch this first.
- [ CRITICAL ] CVE-2026-63077 JetBrains TeamCity On-Prem Unauthenticated RCE
Found this useful? Share it.
