← Back

Wire · technology

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

Published

28 July 2026

Topic

technology

Sectors

CybersecurityEnterprise Software

Source

Read at thehackernews.com

Verified

Fusion42 · 28 July 2026 · Fusion42 review

JetBrains disclosed CVE-2026-63077, a critical unauthenticated remote code execution flaw in TeamCity On-Premises (CVSS 9.8) that allows attackers to bypass authentication and execute arbitrary OS commands. Patches are available in versions 2025.11.7 and 2026.1.3, with a plugin available for older versions.

This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software, and 3 sources have reported it between 28 Jul 2026 and 6 Aug 2026.

◆ The Wire takeaway

Your CI/CD pipeline is now a direct attack surface without a login wall. If you run TeamCity on-premises and haven't patched to 2025.11.7 or 2026.1.3 by end of week, your build servers and everything they touch—source code, credentials, deployment keys—are openly accessible.

Coverage

3 sources · first reported 28 Jul 2026 · latest 6 Aug 2026

Related on Wire

Topics

CybersecurityEnterprise Softwareteamcityrce-vulnerabilityunauth-exploitpatch-urgentci-cd-risk