The development team behind a popular self-hosted continuous integration and continuous delivery server warned its customers to take urgent action after it disclosed a near-perfect-10 critical remote code execution (RCE) vulnerability in one of its platforms.
In a 28 July blog post, JetBrains disclosed CVE-2026-63077 (which has a CVSS score of 9.8), impacting its TeamCity On-Premises platform, saying that if it were to be exploited, it “may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands”.
“All versions of TeamCity On-Premises are affected. TeamCity Cloud customers are not required to take any action, as the necessary measures have already been applied,” TeamCity solutions engineer Daniel Gallo said.
“We have verified that there is no evidence of TeamCity Cloud environments being exploited through this vulnerability.”
A fix has been introduced in versions 2025.11.7 and 2026.1.3, while a security patch plug-in has also been released for versions 2017.1 and later. The patch, however, only addresses that specific vulnerability, and JetBrains recommends an upgrade to take advantage of other security updates.
Cyber security firm Rapid7 agrees with JetBrains’ advice to make updating a priority.
“Organisations running TeamCity On-Premises should urgently prioritise updating to a fixed version, either via the TeamCity UI update workflow or by downloading and installing one of the following fixed versions,” the company said in a 29 July blog post.
“In addition to patching, as a defence-in-depth measure, Rapid7 recommends restricting network access to TeamCity servers to only users and systems that must have it.”
The vulnerability was reported to JetBrains by security researcher Antoni Tremblay on 10 July.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.
David Hollingworth
David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.