JetBrains: Update now! JetBrains warns of critical RCE vulnerability in its TeamCity On-Premises platform

JetBrains: Update now! JetBrains warns of critical RCE vulnerability in its TeamCity On-Premises platform

Critical RCE Vulnerability in JetBrains TeamCity On-Premises Requires Immediate Patching

JetBrains has disclosed CVE-2026-63077, a critical remote code execution (RCE) vulnerability affecting its TeamCity On-Premises platform. With a CVSS score of 9.8, the flaw allows unauthenticated attackers with HTTP(S) access to bypass authentication and execute arbitrary OS commands.

The vulnerability was reported by security researcher Antoni Tremblay on 10 July and publicly disclosed by JetBrains in a 28 July blog post. All versions of TeamCity On-Premises are impacted, while TeamCity Cloud users are unaffected, as mitigations have already been applied. JetBrains confirmed no exploitation has been observed in cloud environments.

Patches are available in TeamCity versions 2025.11.7 and 2026.1.3, with a security patch plugin released for versions 2017.1 and later. However, JetBrains recommends upgrading to the latest version for broader security improvements. Cybersecurity firm Rapid7 echoed the urgency, advising organizations to restrict network access to TeamCity servers as a defense-in-depth measure.

The disclosure follows JetBrains’ confirmation that no active exploitation has been detected, but the severity of the flaw underscores the need for immediate action.

Source: https://www.cyberdaily.au/security/13981-update-now-jetbrains-warns-of-critical-rce-vulnerability-in-its-teamcity-on-premises-platform

JetBrains cybersecurity rating report: https://www.rankiteo.com/company/jetbrains

"id": "JET1785400101",
"linkid": "jetbrains",
"type": "Vulnerability",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Technology/Software Development',
                        'name': 'JetBrains TeamCity On-Premises Users',
                        'type': 'Software Users'}],
 'attack_vector': 'HTTP(S) access',
 'date_detected': '2024-07-10',
 'date_publicly_disclosed': '2024-07-28',
 'description': 'JetBrains has disclosed CVE-2026-63077, a critical remote '
                'code execution (RCE) vulnerability affecting its TeamCity '
                'On-Premises platform. The flaw allows unauthenticated '
                'attackers with HTTP(S) access to bypass authentication and '
                'execute arbitrary OS commands. All versions of TeamCity '
                'On-Premises are impacted, while TeamCity Cloud users are '
                'unaffected due to applied mitigations.',
 'impact': {'operational_impact': 'Potential arbitrary OS command execution',
            'systems_affected': 'TeamCity On-Premises (all versions)'},
 'investigation_status': 'No active exploitation detected',
 'post_incident_analysis': {'corrective_actions': 'Patching, network access '
                                                  'restrictions, and upgrading '
                                                  'to latest version',
                            'root_causes': 'Unauthenticated authentication '
                                           'bypass leading to RCE'},
 'recommendations': 'Immediately patch or upgrade TeamCity On-Premises to the '
                    'latest version; restrict network access to TeamCity '
                    'servers as a defense-in-depth measure.',
 'references': [{'date_accessed': '2024-07-28',
                 'source': 'JetBrains Blog Post'},
                {'source': 'Rapid7 Advisory'}],
 'response': {'communication_strategy': 'Public disclosure via blog post',
              'containment_measures': 'Restrict network access to TeamCity '
                                      'servers',
              'recovery_measures': 'Upgrade to latest version',
              'remediation_measures': 'Patches available in TeamCity versions '
                                      '2025.11.7 and 2026.1.3; security patch '
                                      'plugin for versions 2017.1 and later',
              'third_party_assistance': 'Rapid7'},
 'title': 'Critical RCE Vulnerability in JetBrains TeamCity On-Premises '
          '(CVE-2026-63077)',
 'type': 'Remote Code Execution (RCE)',
 'vulnerability_exploited': 'CVE-2026-63077'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.