bleeping-computer · Crawled Jul 30, 2026

JetBrains warns of critical TeamCity remote code execution flaw

Read original article ↗

AI Summary

JetBrains has disclosed a critical authentication bypass vulnerability in TeamCity On-Premises, tracked as CVE-2026-63077, which allows unauthenticated attackers with HTTPS access to bypass authentication via the agent polling protocol and achieve remote code execution with server-level privileges. All on-premises versions of TeamCity are affected, while cloud customers are protected as mitigations are already applied. Successful exploitation could lead to exposure of sensitive data, credentials, build artifacts, and CI/CD pipeline compromise. Although no active exploitation was observed at the time of disclosure, the history of TeamCity targeting by ransomware and state-backed groups underscores the urgency of patching.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.