← Back

Wire · technology

JetBrains patches critical TeamCity flaw enabling unauthenticated code execution

Published

30 July 2026

Topic

technology

Sectors

Developer Tools

Source

Read at scworld.com

Verified

Fusion42 · 30 July 2026 · Fusion42 review

JetBrains has patched a critical vulnerability (CVE-2026-63077) in its TeamCity On-Premises software, which carries a CVSS score of 9.8. The flaw allows unauthenticated attackers to execute arbitrary commands, posing a severe risk to build pipelines and server integrity. Users are strongly advised to update to version 2025.11.7 or 2026.1.3 immediately.

This Wire brief sits within Fusion42's coverage of Developer Tools. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

◆ The Wire takeaway

Your on-premise CI/CD pipeline just became an open gateway for attackers to run any command they want. Patch your TeamCity server this morning; this is not a drill.

Related on Wire

Topics

Developer Toolsjetbrainsteamcityvulnerabilitycicdsecurity-patchrce