CRITICAL
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
JetBrains is urging customers running on-premise TeamCity to update after disclosing CVE-2026-63077 (CVSS 9.8), a critical flaw affecting all TeamCity On-Premises versions that could allow unauthenticated arbitrary code execution. Fixes are available in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already been patched. No mention of active exploitation in the wild.