TeamCity On-Premises unauthenticated RCE (CVE-2026-63077)
Vulnerability
Summary
Hide ▲
Show ▼
JetBrains has patched CVE-2026-63077, a critical unauthenticated RCE flaw affecting all TeamCity On-Premises versions. The issue can let an attacker with HTTP(S) access bypass authentication and run arbitrary operating system commands as the TeamCity server process. Fixes are available in 2025.11.7 and 2026.1.3, and a patch plugin covers 2017.1+ when immediate upgrades are not possible.
Related Happenings
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector Action
H score53
First: 04.02.2026 07:50
Last: 04.02.2026 07:50
Sources 1
About this happening:
CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector ActionAbout this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
IBM API Connect CVE-2025-13915 mitigation guidance
Advisory/Mitigation
H score42
First: 31.12.2025 12:34
Last: 31.12.2025 12:34
Sources 1
About this happening:
IBM told customers to upgrade IBM API Connect to address CVE-2025-13915, a critical authentication bypass that can let unauthenticated attackers reach exposed...
IBM API Connect CVE-2025-13915 mitigation guidance
Advisory/MitigationAbout this happening: IBM told customers to upgrade IBM API Connect to address CVE-2025-13915, a critical authentication bypass that can let unauthenticated attackers reach exposed...
Timeline
-
28.07.2026 11:11 2 articles · 3h ago
TeamCity On-Premises unauthenticated RCE (CVE-2026-63077)
Initial DisclosureJetBrains identified CVE-2026-63077 in TeamCity On-Premises and released patched versions 2025.11.7 and 2026.1.3. The flaw is an unauthenticated RCE issue that can let an attacker bypass authentication and execute commands on the server.
Show sources
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In — thehackernews.com — 28.07.2026 11:11
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In — thehackernews.com — 28.07.2026 11:11