Vulnerabilities

TeamCity On-Premises: patch critical CVE-2026-63077

JetBrains issued fixes for unauthenticated remote code execution in TeamCity On-Premises and later reported attempted exploitation.

Conceptual illustration: TeamCity On-Premises: patch critical CVE-2026-63077
Conceptual illustration · SecurCheck

What is confirmed

JetBrains published its CVE-2026-63077 notice on 27 July: On-Premises deployments are affected, while TeamCity Cloud has already received the necessary protections.

Fixes are in TeamCity 2025.11.7 and 2026.1.3; JetBrains also offers a security patch plugin for certain older releases. The vendor later reported attempted and active exploitation of unpatched servers.

What it means

A CI server can hold deployment secrets and source-code access; compromise warrants review of credentials and build artifacts.

A flaw in a TeamCity server does not mean every project built with TeamCity is infected.

What to do

Upgrade On-Premises instances to a fixed version or install JetBrains' security patch plugin if upgrading must be deferred.

Restrict network exposure, review logs and rotate build tokens or secrets if an intrusion is suspected.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. JetBrains — avis CVE-2026-63077
  2. JetBrains — versions corrigées