JetBrains
Vulnerabilities in JetBrains TeamCity, YouTrack, and other build/collaboration servers — CI/CD infrastructure whose compromise puts the entire downstream software supply chain at risk of build poisoning and artifact tampering.
JetBrains TeamCity On-Prem Unauthenticated RCE
CVSS 9.8 critical. Unauthenticated remote code execution in all JetBrains TeamCity On-Premises versions, fixed in 2025.11.7 and 2026.1.3.
JetBrains TeamCity Relative Path Traversal Vulnerability
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
JetBrains TeamCity Authentication Bypass
An authentication-bypass vulnerability in JetBrains TeamCity's web component allows a remote, unauthenticated attacker to perform admin actions on the CI/CD server, enabling full takeover of build pipelines.
JetBrains TeamCity Authentication Bypass Vulnerability
JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.

JetBrains Cadence Breached via Unpatched TeamCity RCE
AWS keys, source code, and a server backup stolen from JetBrains Cadence after its TeamCity server went unpatched for weeks against CVE-2026-63077.

TeamCity CVE-2026-63077: Agent Protocol Is the Vector
Rapid7's ETR confirms CVE-2026-63077 sits in TeamCity's agent polling protocol — deserialization, no credentials needed. Patch to 2025.11.7 or 2026.1.3.

TeamCity 9.8 RCE Flaw Hits All On-Prem Versions
JetBrains has patched CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in all TeamCity On-Premises versions. Update to 2025.11.7 or 2026.1.3 now.

TeamCity CVE-2024-27198: EPSS 0.999 two years past patch
JetBrains TeamCity's 2024 auth-bypass still ranks EPSS 0.999 more than two years post patch. Internet-facing build servers keep the exposed population alive.