← Back

Wire · technology

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

Published

28 July 2026

Topic

technology

Sectors

Enterprise Software

Source

Read at thehackernews.com

Verified

Fusion42 · 28 July 2026 · Fusion42 review

JetBrains disclosed CVE-2026-63077, a critical unauthenticated remote code execution flaw in TeamCity On-Premises (CVSS 9.8) that allows attackers to bypass authentication and execute arbitrary OS commands. Patches are available in versions 2025.11.7 and 2026.1.3, with a plugin available for older versions.

This Wire brief sits within Fusion42's coverage of Enterprise Software. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

◆ The Wire takeaway

Your CI/CD pipeline is now a direct attack surface without a login wall. If you run TeamCity on-premises and haven't patched to 2025.11.7 or 2026.1.3 by end of week, your build servers and everything they touch—source code, credentials, deployment keys—are openly accessible.

Related on Wire

Topics

Enterprise Softwareteamcityrce-vulnerabilityunauth-exploitpatch-urgentci-cd-risk