What is confirmed
JetBrains published its CVE-2026-63077 notice on 27 July: On-Premises deployments are affected, while TeamCity Cloud has already received the necessary protections.
Fixes are in TeamCity 2025.11.7 and 2026.1.3; JetBrains also offers a security patch plugin for certain older releases. The vendor later reported attempted and active exploitation of unpatched servers.
What it means
A CI server can hold deployment secrets and source-code access; compromise warrants review of credentials and build artifacts.
A flaw in a TeamCity server does not mean every project built with TeamCity is infected.
What to do
Upgrade On-Premises instances to a fixed version or install JetBrains' security patch plugin if upgrading must be deferred.
Restrict network exposure, review logs and rotate build tokens or secrets if an intrusion is suspected.
Use the related SecurCheck tool, then confirm important decisions with an official source.



