← Back

Wire · technology

JetBrains patches critical TeamCity flaw enabling unauthenticated code execution

Published

30 July 2026

Topic

technology

Sectors

Developer Tools

Source

Read at scworld.com

Verified

Fusion42 · 30 July 2026 · Fusion42 review

JetBrains has patched a critical vulnerability (CVE-2026-63077) in its TeamCity On-Premises software, which carries a CVSS score of 9.8. The flaw allows unauthenticated attackers to execute arbitrary commands, posing a severe risk to build pipelines and server integrity. Users are strongly advised to update to version 2025.11.7 or 2026.1.3 immediately.

This Wire brief sits within Fusion42's coverage of Developer Tools, and 3 sources have reported it between 28 Jul 2026 and 6 Aug 2026.

◆ The Wire takeaway

Your on-premise CI/CD pipeline just became an open gateway for attackers to run any command they want. Patch your TeamCity server this morning; this is not a drill.

Coverage

3 sources · first reported 28 Jul 2026 · latest 6 Aug 2026

Related on Wire

Topics

Developer Toolsjetbrainsteamcityvulnerabilitycicdsecurity-patchrce