CVE Record
[ CRITICAL ] CVE-2026-63077
JetBrains TeamCity On-Prem Unauthenticated RCE
CVSS 9.8 critical. Unauthenticated remote code execution in all JetBrains TeamCity On-Premises versions, fixed in 2025.11.7 and 2026.1.3.
- Vendor
- JetBrains
- Product
- TeamCity On-Premises (all versions)
- CVSS
- 9.8
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
Unauthenticated remote code execution in all on-premises versions of JetBrains TeamCity. A remote attacker with network access to the TeamCity port can execute arbitrary operating system commands on the host server without any credentials.
Fixed in 2025.11.7 (LTS branch) and 2026.1.3 (current branch). TeamCity Cloud was patched automatically. No active exploitation confirmed at time of writing; no CISA KEV entry as of 2026-07-28.
Consult JetBrains security advisories and the NVD entry for current status.
