Post
CRITICAL

Critical Code Execution Vulnerability Patched in TeamCity

· cve · rce · devsecops

JetBrains patched a critical vulnerability in TeamCity, tracked as CVE-2026-63077, that allows unauthenticated remote code execution via the agent polling protocol.

Because TeamCity is widely used as CI/CD infrastructure, an unpatched instance could give an attacker a path to compromise build pipelines. No confirmed in-the-wild exploitation was reported at the time of disclosure. Organizations running self-hosted TeamCity servers should apply the patch promptly given the unauthenticated attack vector.