JetBrains TeamCity On-Prem Unauthenticated RCE
CVSS 9.8 critical. Unauthenticated remote code execution in all JetBrains TeamCity On-Premises versions, fixed in 2025.11.7 and 2026.1.3.
- Vendor
- JetBrains
- Product
- TeamCity On-Premises (all versions)
- CVSS
- 9.8
- EPSS (exploit probability)
- 86.5%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
Unauthenticated remote code execution in all on-premises versions of JetBrains TeamCity. A remote attacker with network access to the TeamCity port can execute arbitrary operating system commands on the host server without any credentials.
Fixed in 2025.11.7 (LTS branch) and 2026.1.3 (current branch). TeamCity Cloud was patched automatically.
CISA added CVE-2026-63077 to the Known Exploited Vulnerabilities catalog on August 5, 2026, with a federal remediation deadline of August 8. Active exploitation is confirmed: attackers breached JetBrains’ own Cadence ML platform using this flaw between August 8 and August 23, extracting AWS IAM credentials, a full server backup, and PyCharm project source code. Rapid7 identified the TeamCity agent-listener protocol as a secondary attack surface beyond the main RCE path.
Consult JetBrains security advisories and the NVD entry for current status.
