Find notable cyber news and cases, enriched with sources, timelines, and signals.

TeamCity On-Premises unauthenticated RCE (CVE-2026-63077)

Vulnerability
First reported
Last updated
Happening score
H score 39
1 unique sources, 1 articles

Summary

Hide ▲

JetBrains has patched CVE-2026-63077, a critical unauthenticated RCE flaw affecting all TeamCity On-Premises versions. The issue can let an attacker with HTTP(S) access bypass authentication and run arbitrary operating system commands as the TeamCity server process. Fixes are available in 2025.11.7 and 2026.1.3, and a patch plugin covers 2017.1+ when immediate upgrades are not possible.

Related Happenings

CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551

Public Sector Action
H score53 First: 04.02.2026 07:50 Last: 04.02.2026 07:50 Sources 1

About this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...

IBM API Connect CVE-2025-13915 mitigation guidance

Advisory/Mitigation
H score42 First: 31.12.2025 12:34 Last: 31.12.2025 12:34 Sources 1

About this happening: IBM told customers to upgrade IBM API Connect to address CVE-2025-13915, a critical authentication bypass that can let unauthenticated attackers reach exposed...

Timeline

  1. 28.07.2026 11:11 2 articles · 3h ago

    TeamCity On-Premises unauthenticated RCE (CVE-2026-63077)

    Initial Disclosure

    JetBrains identified CVE-2026-63077 in TeamCity On-Premises and released patched versions 2025.11.7 and 2026.1.3. The flaw is an unauthenticated RCE issue that can let an attacker bypass authentication and execute commands on the server.

    Show sources