Wire · technology
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 28 July 2026 · Fusion42 review
JetBrains disclosed CVE-2026-63077, a critical unauthenticated remote code execution flaw in TeamCity On-Premises (CVSS 9.8) that allows attackers to bypass authentication and execute arbitrary OS commands. Patches are available in versions 2025.11.7 and 2026.1.3, with a plugin available for older versions.
This Wire brief sits within Fusion42's coverage of Enterprise Software. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ ◆ The Wire takeaway
Your CI/CD pipeline is now a direct attack surface without a login wall. If you run TeamCity on-premises and haven't patched to 2025.11.7 or 2026.1.3 by end of week, your build servers and everything they touch—source code, credentials, deployment keys—are openly accessible.
◆ Related on Wire
◆ Topics