← Back

Wire · regulatory

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)

Published

28 July 2026

Topic

regulatory

Sectors

Developer ToolsCybersecurity

Source

Read at helpnetsecurity.com

Verified

Fusion42 · 28 July 2026 · Fusion42 review

JetBrains has patched CVE-2026-63077, a critical unauthenticated remote code execution vulnerability in TeamCity On-Premises that allows attackers to bypass authentication and execute OS commands with server privileges. State-sponsored groups and ransomware affiliates have historically targeted unpatched TeamCity instances; admins must upgrade to versions 2025.11.7 or 2026.1.3, or apply the security patch plugin.

This Wire brief sits within Fusion42's coverage of Developer Tools and Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

◆ The Wire takeaway

Every build pipeline running self-hosted TeamCity right now is an open door to your production environment until you patch. The vulnerability runs the attacker's code as your build server, which means they own your artifacts, your secrets, and your downstream deployments.

Related on Wire

Topics

Developer ToolsCybersecurityteamcity-rceauthentication-bypassci-cd-riskpatch-urgencysupply-chain-attack