TeamCity security patch release for CVE-2026-63077
Security Patch Release
Summary
Hide ▲
Show ▼
JetBrains released TeamCity On-Premises fixes for CVE-2026-63077, a critical unauthenticated remote code execution issue, through 2025.11.7, 2026.1.3, and a security patch plugin for 2017.1+.
Related Happenings
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch Release
H score55
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch ReleaseAbout this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
Ivanti security patch release for CVE-2026-8043
Security Patch Release
H score25
First: 18.05.2026 13:54
Last: 18.05.2026 13:54
Sources 1
About this happening:
Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Ivanti security patch release for CVE-2026-8043
Security Patch ReleaseAbout this happening: Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Storm-1175 high-tempo Medusa ransomware campaign
Campaign
H score59
First: 07.04.2026 13:02
Last: 07.04.2026 13:02
Sources 1
About this happening:
Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-tempo Medusa ransomware campaign
CampaignAbout this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Hewlett Packard Enterprise (HPE) security patch release for CVE-2026-23813
Security Patch Release
H score69
First: 10.03.2026 19:30
Last: 10.03.2026 19:30
Sources 1
About this happening:
HPE released security updates for Aruba Networking AOS-CX, closing multiple vulnerabilities including authentication and code execution issues on CX-series campu...
Hewlett Packard Enterprise (HPE) security patch release for CVE-2026-23813
Security Patch ReleaseAbout this happening: HPE released security updates for Aruba Networking AOS-CX, closing multiple vulnerabilities including authentication and code execution issues on CX-series campu...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector Action
H score53
First: 04.02.2026 07:50
Last: 04.02.2026 07:50
Sources 1
About this happening:
CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector ActionAbout this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
Timeline
-
28.07.2026 11:11 1 articles · 3h ago
Antoni Tremblay discovers CVE-2026-63077 in TeamCity
Technical Analysis UpdateJetBrains credited Antoni Tremblay with discovering and reporting CVE-2026-63077 on July 10, 2026. The flaw affects all TeamCity On-Premises versions and can let an unauthenticated attacker with HTTP(S) access bypass authentication checks and execute arbitrary operating system commands.
Show sources
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In — thehackernews.com — 28.07.2026 11:11
-
28.07.2026 11:11 2 articles · 3h ago
JetBrains releases TeamCity fixes for CVE-2026-63077
Mitigation Patch UpdateJetBrains said it had released TeamCity versions 2025.11.7 and 2026.1.3 and a security patch plugin for versions 2017.1+ to address CVE-2026-63077. TeamCity Cloud instances had already been updated, and the plugin is limited to the cited vulnerability.
Show sources
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In — thehackernews.com — 28.07.2026 11:11
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In — thehackernews.com — 28.07.2026 11:11